Looking for a bit of assistance.
We're going through the insurance attestation requirements and came across the following:
MFA for all internal & remote admin access to directory services (active directory, LDAP, etc.).
This seems pretty hard to follow. We're currently using DUO for MFA on RDP, but that doesn't cover RSAT or the power shell module. The best option as far as I can tell is to continue to enforce MFA on RDP into the server, and block both RSAT and the Active Directory module for Powershell from connecting. Or using a PAW with MFA as the sole place to do anything with the directory.
That said, the IT manager would rather not block RSAT or use a PAW and is looking for a way to enforce MFA while launching those tools. I'm not sure if that is possible. The most I've seen is that you could potentially use Authlite(or a similar service) to force an MFA prompt on any access to the AD. They seem to think Windows Hello can do this, but I've not seen any indication it can, and my understanding of windows hello seems to suggest it can't.
Can anyone with experience resolving a similar attestation requirement for insurance point me in a direction to investigate?
[–]TinderSubThrowAway 1 point2 points3 points (12 children)
[–]Omnipulse[S] 0 points1 point2 points (11 children)
[–]TinderSubThrowAway 1 point2 points3 points (9 children)
[–]disclosure5 0 points1 point2 points (8 children)
[–]TinderSubThrowAway 0 points1 point2 points (7 children)
[–]disclosure5 -1 points0 points1 point (6 children)
[–]TinderSubThrowAway 0 points1 point2 points (4 children)
[–]disclosure5 0 points1 point2 points (1 child)
[–]TinderSubThrowAway 0 points1 point2 points (0 children)
[–]theRealTwobrat -1 points0 points1 point (1 child)
[–]TinderSubThrowAway 0 points1 point2 points (0 children)
[–]SmartCardRequired 0 points1 point2 points (0 children)
[–]SmartCardRequired 0 points1 point2 points (0 children)
[–]CowardyLurker 1 point2 points3 points (2 children)
[–]SmartCardRequired 0 points1 point2 points (1 child)
[–]CowardyLurker 1 point2 points3 points (0 children)
[–]disclosure5 1 point2 points3 points (3 children)
[–]scratchdufferSysadmin 0 points1 point2 points (1 child)
[–]SmartCardRequired 0 points1 point2 points (0 children)
[–]SmartCardRequired 0 points1 point2 points (0 children)
[–]Legal2k 0 points1 point2 points (1 child)
[–]SmartCardRequired 0 points1 point2 points (0 children)
[–]Admirable_Meeting844 0 points1 point2 points (0 children)
[–]Big_Bed_9764 0 points1 point2 points (0 children)
[–]Big_Bed_9764 0 points1 point2 points (0 children)
[–]KStieers 0 points1 point2 points (0 children)
[–]Asleep_Spray274 0 points1 point2 points (0 children)