What are people's thoughts on this now that Google Auth can sync OTP to multiple devices when signed into the Google account?
For example, our environment (as probably every other environment) has these types of "Service Accounts", such as "president@domain.tld" or "printing@domain.tld" or "admissions@domain.tld". These accounts, due to not having a viable option for MFA (as multiple people sign into these accounts), currently don't require MFA to be enabled.
Now that Google Auth has the sync functionality, do people think it would be a viable option to require all the users who access these accounts to have the Google Authenticator app installed on their mobile device, and sync the OTP with the "Service Account" so that the 4 people in Admissions can sign into the account with MFA?
My only concern would be if one of these people lost their device (or were terminated, or were phished as in a previous post), security-wise, it doesn't sound like a sound idea to have this, but how do we best protect these accounts?
Google Edu Fund. version so access control is out of the picture unfortunately