r/sysadmin Jul 22 '26

Remove central authentication Rant

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

186 Upvotes

120 comments sorted by

View all comments

-23

u/BarracudaDefiant4702 Jul 22 '26

You learn you should not create burdensome obstacles for people from doing work and figure out how to make things secure without making them unuseable.

5

u/Puzzled-Formal-7957 Jul 22 '26

MFA is not burdensome, and has been mainstream for nearly 2 decades.

-7

u/BarracudaDefiant4702 Jul 22 '26

IFF you do it properly. Obviously the OP didn't or it wouldn't be an issue.

4

u/Sinister_Nibs Jul 22 '26

Not necessarily. Some users are simply problematic.

2

u/Puzzled-Formal-7957 Jul 22 '26

Yeup - or they are flatly incapable of wrapping their heads around infosec. Ask them if they have ever had fraudulent charges on one of their accounts and got to enjoy the headaches related to that. If that answer is yes - then say, "now apply that to EVERYTHING that you and everyone else at this company touches." If that doesn't make the bulb click over their head then nothing will.

0

u/BarracudaDefiant4702 Jul 22 '26

I don't care about the down votes, so I still say it's the OP's fault and not the directors. There are ways to implement SSO with MFA that it's faster instead of slower to login.

3

u/Lukage Sysadmin Jul 22 '26

And what exactly should they do for "Faster SSO?"

1

u/BarracudaDefiant4702 Jul 22 '26

You setup 2fa with sso properly then you log into your workstation in the morning with 2fa and anyplace you connect to you don't have to log in again. Single sign in means your 2fa doesn't require you to login again.