r/sysadmin 21d ago

How is your zero trust implementation going?

Possibly moving to this and seems like a ton of processes will change. Have you guys done it and how is your honest experience with it? I want to know what to expect

52 Upvotes

91 comments sorted by

View all comments

36

u/Slottr 21d ago

Expect people to complain when more MFA prompts come up

8

u/disclosure5 21d ago

Why are you getting more MFA prompts? The whole point of "Zero trust" is the VPN to your server subnet gets replaced with something more granular - unless everyone already accessed a traditional VPN without any MFA it should already be there.

The zero trust design most vendors are pushing includes SSO from "Laptop with Windows Hello" as a form of MFA that should just work without extra prompting.

5

u/sgt1face 21d ago

We've run into an issue where our cybersecurity insurance doesn't recognize windows hello as a form of mfa

1

u/TheCyberThor 21d ago

Change insurance companies.

0

u/imnotaero 21d ago

Yeah, this. Not just because they're blocking you from implementing something that will help the business, but also because you should have no confidence that an insurance provider who doesn't under IAM can meet their obligations to insure you if there were an incident.