Hello All,
I've been investigating implementing MFA on our FAS/AFF systems. We took the active decision to use local accounts on these systems so that a compromise of our Active Directory didn't also result in access to our storage estate.
Generally, I logon via SSH and setting up TOTP MFA is pretty simple and works ok. But for HTTPS access, there is no documented way to add MFA to a local account logging in via HTTPS, at least not that I could find but I'm happy to be corrected. However, in System Manager, there the option to add MFA to the account is presented; so I tried on our test system. I was expecting to get a QR code to scan to add TOTP but instead my password manager prompted me to save a Passkey. I was a little surprise.
Now when I login, I always have to provide a password and passkey. So in principle, this meets the 2FA requirement. I just have to persuade our auditors that this is a Cyber Essentials compliant method.
Just wondering if anyone else has gone down this route and what success they've had with their auditors.
Regards,
Mark