It’s about security: Access to OTP in RDM is only granted after verification
1 vote
RDM enables rapid access to a company’s entire IT infrastructure, but what if it falls into the wrong hands?
I would very much welcome it if at least the final access barrier to a system – the OTP – were only authorised by the RDM following an additional verification step. Or, for critical systems, perhaps even access to the password itself.
I could envisage this being done either via a smartphone app, which receives a push notification and requires access to be authorised via biometrics, or via a FIDO2 key (YubiKey).
Personally, I wouldn’t mind having to tap my YubiKey or confirm access on my mobile every time I access a system; it’s quick to do and offers a significant additional layer of protection.
Hi @jensvolkmer,
If I understand correctly, your request would be to have MFA checks when accessing entries similar to what we've done for Devolutions PAM? https://devolutions.net/blog/mfa-at-pam-checkout-confirming-identity-the-moment-it-matters/
If that is the case, we don't currently plan on expanding MFA checks to our checkout process on non privileged credentials, but we'll keep it noted on our end. In the mean time, we recommend using our Privileged Access Management platform for such use-cases.
Cheers,
Luc Fauvel