MFA Email Factor for Users with Registered Accounts
- What is the problem that this feature would fix?
I would like an option to allow Email OTP for a factor of MFA. In some scenarios having an TOTP QR Code is not required and causes unneeded burden for quick access.
- Why is it a problem?
New User Accounts setting up accounts are slowed down by QR Code setup and some accounts are used rarely causing administrative burden when Email OTP would suffice for risk.
- Is there a workaround you currently have for this problem?
No
- Do you have a suggestion on how you would like to see the problem fixed?
Allow Email OTP for Regular (User + Password) Accounts like currently existing for Share Links, in place of TOTP codes. We use Native Accounts for Third Parties and SSO Accounts for Internal Users. Third Parties sometimes struggle with the OTP as they are not allowed to use Personal Devices.
- How big is the problem? Who is affected by this problem (End Users, Admins, etc.)?
End Users and Administrators who support MFA Resets
-
Hello,
Thank you for submitting this enhancement request! We have raised this type of enhancement to our product and engineering teams in the past, and it was determined that email based OTP for MFA is considered insecure, and they had decided to not go down the path of implementation due to the security risk. However, I do believe DUO carries some of this functionality, and DUO Is already supported within Cerberus. That is what we tend to suggest to folks looking for email based OTP for MFA.
0 -
Hi Connor,
I understand the concern however Duo requires 3$/month/user and requires additional overhead to provision ad hoc third-party vendors which use our system a few times a year. Email OTP would be a preferred usage as we use CerberusFTP for B2B. It would be a nice feature and allow us to assess risk for our use case, if you allowed the administrator to select acceptable MFA assigned by Group that would be great.
Our issue is within regulated spaces cellphones and new software are not permitted or requires extensive review. The usage of Duo would require SMS, Duo Push or us shipping hardware tokens to vendors, while every business has email. CerberusFTP excels in it's ability to work in regulated spaces while being able to selfhost and having a limitation. We assess vendor email risk outside Cerberus and allowing this flexibility would be great. May I ask this option to be reconsidered?
Feel free to reach out via email if you'd like to understand our use case and reasoning behind this request.
0
Please sign in to leave a comment.
Comments
2 comments