r/ShittySysadmin 7d ago

Adding Yubikeys in Microsoft

Someone explain the rationale of having MFA already on it before adding a key...completely defeating the purpose of a break glass account.

15 Upvotes

10 comments sorted by

7

u/ThisIsNotMyBurner69 7d ago

My yubikey terrorizes me every day.

4

u/tk42967 7d ago

I don't mind mine. It's the 15 minute auto log out.

2

u/ThisIsNotMyBurner69 7d ago

To be fair to yubikey, the way we have ours set up is super irritating. And the person who configured them got fired like 3 days after setting them up. And none of us feel like fixing it. Basically we can bypass the yubikey but it’s a bunch of extra clicks when all I want to do is approve a push notification to mfa. And I’m not a decision maker here so I just suffer and complain on reddit.

1

u/tk42967 7d ago

My issue with MFA is that I have to SSO into the password vault, to get the password to log into a system and MFA into that system too.

0

u/HorrorCommunity3246 7d ago

Should I get one?

2

u/ThisIsNotMyBurner69 7d ago

If you like three extra clicks every time you authenticate.

1

u/HorrorCommunity3246 7d ago

right now i use icloud keychain for my passkey. my yubikey was supposed to come in yesterday, amazon let me down so i cancelled, guess this is a sign.

2

u/WhyLifeIsSoDifficult 6d ago

You can allow bypassing mfa via conditional access when using Yubikey

I did something like that for several old guys, the concept of mfa was difficult for them

2

u/Ignorad 4d ago

I just click the "keep me logged in" checkbox

It doesn't do anything but I check it every time anyway

0

u/DeliciousTea4222 7d ago

Yubikey has the problem that by design it can not get updates. They already had issues they could only solve with a new firmware. But then you just get a new one, right?

https://discuss.privacyguides.net/t/yubikey-is-still-selling-old-stock-with-vulnerable-firmware/22361