<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using (requiring) Google Authenticator and Sync for &amp;quot;Service Accounts&amp;quot; in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1130#M778</link>
    <description>&lt;P&gt;What are people's thoughts on this now that Google Auth can sync OTP to multiple devices when signed into the Google account?&lt;/P&gt;&lt;P&gt;For example, our environment (as probably every other environment) has these types of "Service Accounts", such as "president@domain.tld" or "printing@domain.tld" or "admissions@domain.tld". These accounts, due to not having a viable option for MFA (as multiple people sign into these accounts), currently don't require MFA to be enabled.&lt;/P&gt;&lt;P&gt;Now that Google Auth has the sync functionality, do people think it would be a viable option to require all the users who access these accounts to have the Google Authenticator app installed on their mobile device, and sync the OTP with the "Service Account" so that the 4 people in Admissions can sign into the account with MFA?&lt;/P&gt;&lt;P&gt;My only concern would be if one of these people lost their device (or were terminated, or were phished as in a previous post), security-wise, it doesn't sound like a sound idea to have this, but how do we best protect these accounts?&lt;/P&gt;&lt;P&gt;Google Edu Fund. version so access control is out of the picture unfortunately&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Sep 2023 15:33:34 GMT</pubDate>
    <dc:creator>alexgrutza</dc:creator>
    <dc:date>2023-09-26T15:33:34Z</dc:date>
    <item>
      <title>Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1130#M778</link>
      <description>&lt;P&gt;What are people's thoughts on this now that Google Auth can sync OTP to multiple devices when signed into the Google account?&lt;/P&gt;&lt;P&gt;For example, our environment (as probably every other environment) has these types of "Service Accounts", such as "president@domain.tld" or "printing@domain.tld" or "admissions@domain.tld". These accounts, due to not having a viable option for MFA (as multiple people sign into these accounts), currently don't require MFA to be enabled.&lt;/P&gt;&lt;P&gt;Now that Google Auth has the sync functionality, do people think it would be a viable option to require all the users who access these accounts to have the Google Authenticator app installed on their mobile device, and sync the OTP with the "Service Account" so that the 4 people in Admissions can sign into the account with MFA?&lt;/P&gt;&lt;P&gt;My only concern would be if one of these people lost their device (or were terminated, or were phished as in a previous post), security-wise, it doesn't sound like a sound idea to have this, but how do we best protect these accounts?&lt;/P&gt;&lt;P&gt;Google Edu Fund. version so access control is out of the picture unfortunately&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 15:33:34 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1130#M778</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-26T15:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1131#M779</link>
      <description>&lt;P&gt;Just No.&lt;/P&gt;&lt;P&gt;Use Delegated Gmail or a Group for those addresses.&lt;/P&gt;&lt;P&gt;Several people logging into the same account is a breach of the Acceptable Use Policy, and also contrary to any security and data privacy law, in the world basically.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 15:45:56 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1131#M779</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-26T15:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1134#M780</link>
      <description>&lt;P&gt;1.1) I would agree about the delegated access would most likely be the best route (assuming they don't also need the accounts Google Drive data, ie. something like &lt;A href="mailto:marketing@domain.tld" target="_blank"&gt;marketing@domain.tld&lt;/A&gt;&amp;nbsp;may have marketing materials, which should be in a Shared Drive rather, but that's unfortunately not the world/company we live in...sadly the previous Google Admins (some here, some gone) blame Google for not having all the functionality they have nowadays back in '09...)&lt;/P&gt;&lt;P&gt;1.2) if we were to go the route of delegated Gmail, we'd still want to enable/force MFA for these accounts, but what would that look like? Yubikey's that sit in a drawer and are labeled? MFA on an IT person's mobile phone?&lt;/P&gt;&lt;P&gt;2.1) &lt;STRONG&gt;Devils advocate and rhetorical&lt;/STRONG&gt;: the Admin Google account that was created to set up the Workspace account originally, how many people have access to log into that account? More than one I bet in case the one person got hit by a bus or became rouge...so by design all organizations (I would imagine) are breaking the AUP...&lt;/P&gt;&lt;P&gt;2.2) "Luckily" we're in the USA and the users accessing these service type accounts are the intended people/recipient so the privacy law wouldn't apply. The people accessing the "admissions" account for example, are the people who have the legal authority/obligations to view this type of data. It's not some random employee who shouldn't be privy to the data.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 16:01:21 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1134#M780</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-26T16:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1135#M781</link>
      <description>&lt;P&gt;1.1 Yes, common content should be in a Shared Drive anyway.&lt;/P&gt;&lt;P&gt;1.2 Random password that nobody knows will keep users out.&lt;/P&gt;&lt;P&gt;gam update user username password random&amp;nbsp;&lt;/P&gt;&lt;P&gt;That will set a crazy long password.&lt;/P&gt;&lt;P&gt;You could also add a Yubikey, or create backup codes and put in a safe.&lt;/P&gt;&lt;P&gt;2.1 Same with this account. It should be for emergency only, with credentials and 2FA safely tucked away.&lt;/P&gt;&lt;P&gt;2.2 Well, I have heard that many are forced to adhere to strict security rules to qualify for cyber insurance, so I wouldn't bet my house on that assumption.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 16:31:56 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1135#M781</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-26T16:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1136#M782</link>
      <description>&lt;P&gt;Can you have multiple yubikeys associated with a single account?&lt;/P&gt;&lt;P&gt;Can you purchase licenses with the Access Control for a subset of users (say at most 300 accounts)? That would at least narrow down the login ability to our IP ranges which we own.&lt;/P&gt;&lt;P&gt;The Cyber insurance coverage is a good thought in practice, but when they say "you need data at rest encryption" and don't specify if "SED's" are good enough, I'm not sure they'd get as granular as what you're thinking. Insurance loves to be vague so they can reject claims.&lt;/P&gt;&lt;P&gt;Lets just say they didn't mention anything about revoking Local Administrator access to our users...and here we are...covered by insurance with everyone and their mothers having Local Administrator group membership ha..ha..ha...&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":expressionless_face:"&gt;😑&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":loudly_crying_face:"&gt;😭&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 16:49:22 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1136#M782</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-26T16:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1150#M783</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Multiple Yubikeys&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Oh, yes, definitely! I usually have three connected to each account, as I have two I use for different devices, and one backup which I rarely connect.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Context Aware Access&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;No, this is part of Standard/Plus licencing, which is now based on active students, and not staff.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Local Admin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Yup, it's a delicate balance, but I've read so many articles on why&amp;nbsp;&lt;EM&gt;local&lt;/EM&gt; admin isn't the boogey man it's been painted as, since even as non-admin you can do serious damage to both local and remote &lt;EM&gt;files&lt;/EM&gt;, if hit by ransomware. you just can't mess up the system OS files, but many ransomware processes don't even have that as a goal.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 07:19:16 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1150#M783</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-27T07:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1160#M784</link>
      <description>&lt;P&gt;The multiple yubikeys may be the route for us for these type of accounts then, with a few spares. Is there a limit? I know when setting up Passkeys there was like a list of 5 items. So I wasn't sure if there is a limit of 5 per account, or as you get closer to 5 it expands further.&lt;/P&gt;&lt;P&gt;That is a fair point about ransomware not really targeting OS level stuff and going more so for files and folders the user has access to. But alas, that's also a wild west haha... People love asking us to add users to file share resources, but never to remove them...&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 13:14:06 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1160#M784</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-27T13:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1162#M785</link>
      <description>&lt;P&gt;One should always have more than one MFA method, but as nobody should need to log into the accounts you mentioned, all MFA methods should be archived. Orrrrr, well, you don't need to use special Yubikeys as your superadmins could just add their keys to the accounts.&lt;/P&gt;&lt;P&gt;Again, since nobody is supposed to ever log in, it doesn't really matter whose Yubikeys are added.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 13:41:21 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1162#M785</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-27T13:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1173#M786</link>
      <description>&lt;P&gt;What about your main SuperAdmin account for GAC?&amp;nbsp; What method of MFA are folks using for this account?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 17:24:25 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1173#M786</guid>
      <dc:creator>Kelly_McMahon</dc:creator>
      <dc:date>2023-09-27T17:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1174#M787</link>
      <description>&lt;P&gt;Would that be the account under "Account-&amp;gt;Account Settings-&amp;gt;Primary Admin"?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 17:28:11 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1174#M787</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-27T17:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1175#M788</link>
      <description>&lt;P&gt;Exactly, yes, the primary admin.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 17:42:39 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1175#M788</guid>
      <dc:creator>Kelly_McMahon</dc:creator>
      <dc:date>2023-09-27T17:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1176#M789</link>
      <description>&lt;P&gt;It will be using MFA now that I realized it was not already set up as such...&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 17:56:47 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1176#M789</guid>
      <dc:creator>alexgrutza</dc:creator>
      <dc:date>2023-09-27T17:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using (requiring) Google Authenticator and Sync for "Service Accounts"</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1180#M790</link>
      <description>&lt;P&gt;Any superadmin can be the primary admin.&lt;/P&gt;&lt;P&gt;I am primary for two completely separate and unrelated Workspace accounts.&lt;/P&gt;&lt;P&gt;Simply because someone needs to receive those emails which Google sends only to the primary admin.&lt;/P&gt;&lt;P&gt;Yes, yes, this is yet another &lt;EM&gt;Do as I say, not as I do&lt;/EM&gt; situations. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;One should never 🫣&lt;span class="lia-unicode-emoji" title=":crossed_fingers:"&gt;🤞&lt;/span&gt;use their admin account as their daily and instead set up a Routing rule for incoming emails to the admin account forwarded to your daily account.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 19:41:24 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Using-requiring-Google-Authenticator-and-Sync-for-quot-Service/m-p/1180#M790</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-09-27T19:41:24Z</dc:date>
    </item>
  </channel>
</rss>

