What Authentication Should Users Complete Before Accessing an Internal Network Remotely?

0
0
Asked By MellowHarbor42 On

We are mostly cloud-based but still have a legacy on-premises service that staff need to access for things such as terminal services, network drives, printers, and directory-integrated applications. Previously, users logged into their laptops with a password and then enabled a firewall-hosted VPN client. The VPN credential was provisioned through a one-time invitation and associated with the user's identity account, with the device storing the necessary credential securely.

An assessor raised concerns that this setup effectively allows the external service to be accessed using only something the user knows, and suggested that multifactor authentication may be required for VPN connections. I'm trying to understand what authentication sequence other organizations use, including whether MFA is performed every time the VPN connects, periodically, or only when the device or user is initially enrolled.

How do always-on VPN deployments handle this? Would device certificates stored in a TPM, password or biometric laptop login, periodic identity-provider reauthentication, or MFA at the individual application level satisfy the security requirement?

5 Answers

Answered By SilverMaple31 On

A device certificate stored in the TPM can prove that the connection is coming from an enrolled, managed device. It is often combined with a user password, biometric, or identity-provider authentication. That addresses device trust, but it does not necessarily replace MFA for the user, especially where policy requires two independent factors.

Answered By BrightPebble56 On

Another design is to minimize what the VPN exposes. Use the tunnel for connectivity or service discovery, while each application still requires strong authentication and authorization. In a zero-trust model, gaining network access alone does not grant access to file shares, remote desktops, or administrative services. For some organizations, replacing broad network VPN access with application-specific access is simpler and safer.

Answered By OakWindow19 On

For internal wired and wireless access, 802.1X with certificates is another pattern. The same managed-device certificate can authenticate the device across network connections, while user identity and application controls provide the additional authorization layer. The exact requirement depends on the assessor’s interpretation and the organization’s risk assessment, so the written control and session policy matter as much as the VPN product.

Answered By CedarLane88 On

A common approach is an always-on access client tied to the identity provider. The user signs into the laptop with a password or biometric, and the client uses the device and user identity to provide access. Periodic reauthentication is still required, with the frequency and MFA requirements based on policy, risk, and sometimes the user’s location. The VPN connection itself should not automatically be treated as authorization to every internal service.

Answered By QuietComet7 On

Some environments use a more explicit sequence: sign into the laptop, open the VPN client, complete identity-provider authentication and MFA, then connect to the required desktop or application. Sessions may be limited to a fixed period such as 12 hours, after which the user must authenticate again. This is more cumbersome, but it makes the authentication event and session lifetime clear.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.