Is There a Way to Configure RSA MFA to Fail Open During Outages?

0
10
Asked By TechieNinja42 On

I'm curious if there's a way to set up the RSA MFA application on Windows workstations so that it can fail open when the RSA appliance or replicas become unreachable. The idea is that when the network goes down, users can still log in, and once connectivity is restored, they would be prompted for MFA again. I've heard about Duo's fail open functionality and wonder if something similar exists for RSA. Any thoughts?

4 Answers

Answered By RealWorldOps On

I had a similar situation where our RSA service was taken down recently, and no one could authenticate, even though the identity routers appeared fine. If we'd configured a fail-open, that could have led to a lot of problems!

Answered By SkepticalSammy On

I really hope there's no way to do that! Allowing the system to fail open sounds risky to me. It could open the door for unauthorized access, making your security measures pretty useless in the long run.

Answered By TestingGuru99 On

Are you considering this for pre-production tests or some high-risk maintenance period? I agree with the others; it's not a good idea in a live setting. The risks just outweigh the benefits.

Answered By ConcernedAdmin88 On

Honestly, wouldn't this just let anyone dodge MFA by simply blocking it? This could lead to all sorts of vulnerabilities, and I definitely see why you'd want to avoid this approach.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.