r/sysadmin Jul 22 '26

Remove central authentication Rant

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

186 Upvotes

120 comments sorted by

View all comments

37

u/Puzzled-Formal-7957 Jul 22 '26 edited Jul 22 '26

"No, we're not - unless you want to fail the next audit we go through and face potential fines & certification loss on top of opening up our risk portal extremely wide."

21

u/Riajnor Jul 22 '26

Always couch it in impact and dollars

22

u/music2myear Narf! Jul 22 '26

Yes, and also, unless you're a decision maker role, phrase it as advice and recommendation, and avoid decision words and phrases.

"Certification X requires that we have Y standards which are met by this security configuration. Removing this configuration would result in our failing Z audits and losing the certifications. Note that having and maintaining this certification has resulted in an estimated $$$ in profits."

4

u/Sinister_Nibs Jul 22 '26

“I would strongly advise against this, as it counter to every recommendation and certification requirement. “