Use same 2FA in RDM from DVLS datasource - QoL

Use same 2FA in RDM from DVLS datasource - QoL

1 vote

avatar

Hello Devolutions community,

my company is currently using RDM (V2026.2.16.0) and an DVLS (V2026.2.14.0) as the datasource. For security reasons we also have 2FA in the DVLS (DVLS settings) and the RDM (GPO-template for ActiveDirectory) enabled separately. It is necessary to do it in both components, because opened session would be unprotected, if i whould is use the automatic "datasource disconnect"-feature for RDM from the DVLS-settings.

Due to this constellation we have to separete TOTP-Entries in our Microsoft Authententicator.

My question/request now is to simplify that, so that i only have one TOTP-Entry for both components, if that is possible. What i would like to see if you could choose "use TOTP from DVLS-datasource" in the security settings from the RDM.

Is ths possible or is there a better solution that i dont know?

If further information is needed, let me know.

Thanks i advance for your afforts and feedback.

Cheers,
Markus

All Comments (2)

avatar

Hi @markusburkhardt,

Thank you for reaching out. It currently wouldn't be possible to use the same TOTP entry for both as the TOTP secret stored in DVLS cannot be transferred out of the server to RDM as the local TOTP feature in RDM requires the TOTP secret to be validated locally.

Maybe an alternate approach would be for us to add a setting that automatically closes opened sessions when disconnected from the datasource, to be used in combination with the "Automatic datasource disconnect" feature?

Cheers,

Luc Fauvel

avatar

Hi @Luc Fauvel

thanks for the quick response.

Your approach also sounds not to bad and whould help me actually. Closing the session thought is quite hard in my use case, because i need to ask for the 2FA on every lock of windows, after 15 minutes of inactivity or closing RDM. What in my opinion wouhld be better is to "lock" the sessions from the corresponding datasources, so the user get´s the chance just to start working of where he left off. I don´t know how much affort that takes on your end.

Either way opened sessions on a disconnected datasource should be protected someone so the dont become a potential attack vector.

Cheers,

Markus