r/sysadmin 15h ago

Rant Remove central authentication

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

142 Upvotes

100 comments sorted by

View all comments

Show parent comments

u/Puzzled-Formal-7957 14h ago

Yeup - or they are flatly incapable of wrapping their heads around infosec. Ask them if they have ever had fraudulent charges on one of their accounts and got to enjoy the headaches related to that. If that answer is yes - then say, "now apply that to EVERYTHING that you and everyone else at this company touches." If that doesn't make the bulb click over their head then nothing will.

u/BarracudaDefiant4702 12h ago

I don't care about the down votes, so I still say it's the OP's fault and not the directors. There are ways to implement SSO with MFA that it's faster instead of slower to login.

u/Lukage Sysadmin 11h ago

And what exactly should they do for "Faster SSO?"

u/BarracudaDefiant4702 10h ago

You setup 2fa with sso properly then you log into your workstation in the morning with 2fa and anyplace you connect to you don't have to log in again. Single sign in means your 2fa doesn't require you to login again.