[Ext] Re: Forcing Duo by Service Provider

Andrew Morgan morgan at orst.edu
Fri Mar 31 18:14:59 EDT 2017


On Fri, 31 Mar 2017, Bryan Wooten wrote:

> This has been an interesting conversation.
>
> But in my opinion requiring MFA for some apps and not others is just 
> added complication to the underlying issue that passwords alone are 
> insufficient for all access.
>
> I believe it just adds to user confusion and more help desk calls.
>
> We went from 1k users using MFA to over 30k in 6 weeks. All employees 
> are required to use MFA for all Web apps whether the app is SaaS / SAML 
> or in house CAS.
>
> But this is a policy decision not a technical one. Policy decisions can 
> create technical complexity.

Agreed!  A simple solution is to use MFA all the time for people that have 
enrolled in MFA (and require certain populations to enroll).

I'm investigating all of our possibilities to inform our policy-making 
process.  We want to know what is possible, and how difficult it is, for 
all of the scenarios we have dreamed up.  :)

 	Andy



More information about the users mailing list