Skip to main content
Question

MFA / Microsoft Authenticator bypass ?


Nikos.Kyrm
Byte
Forum|alt.badge.img+13

Hello team!

In case of enabling mfa for ALL users / groups, Im wondering if there is any “backdoor” for admin user.

In case of lost Microsoft Authenticator app and email access, is there any way to restore access to Commcell, even with help of Commvault supoprt?

I cant decide if it’s preferred to enable mfa for all admins (master) users or to leave one admin user without mfa (with a strong password) in case of backdoor.

Please for your thoughts.

3 replies

Forum|alt.badge.img+2
  • Vaulter
  • 9 replies
  • March 5, 2024

We've recently introduced a feature to facilitate SAML connectivity testing. This enables you to ensure SAML functionality before enabling it for all users. Furthermore, you can manage associated settings by navigating to the association section. By creating a breakglass user, you can verify that SAML login association doesn't apply to that user. you can setup MFA for this user also using either platform authentication for second factor. 


Forum|alt.badge.img+3
  • Byte
  • 12 replies
  • December 20, 2024

I’m currently facing this issue, I’m doing a DR test restore of the CS, and used the staging option for an environment that is in a bubble. now when I try to login, the admin PWD, I get prompted to enter the MFA token, but it can’t even use it as it is isolated.

 


Nikos.Kyrm
Byte
Forum|alt.badge.img+13
  • Author
  • Byte
  • 204 replies
  • December 20, 2024
G-Dubs wrote:

I’m currently facing this issue, I’m doing a DR test restore of the CS, and used the staging option for an environment that is in a bubble. now when I try to login, the admin PWD, I get prompted to enter the MFA token, but it can’t even use it as it is isolated.

 

In this case, I believe a possible solution is to leave an admin (strong password) backdoor user.

Also, not sure if Commvault Support could assist you.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings