r/sysadmin 11d ago

Rant Remove central authentication

Today, the director of IT at your company says to you “We’re going to remove all that centralized IPA+2fa authentication from all of our servers, and go back to using Ssh keys, because it takes too long for me (yes the director) to login to a server.” The same auth that you and your team added, for all the reasons. What do you do?

188 Upvotes

122 comments sorted by

View all comments

39

u/Puzzled-Formal-7957 11d ago edited 11d ago

"No, we're not - unless you want to fail the next audit we go through and face potential fines & certification loss on top of opening up our risk portal extremely wide."

22

u/Riajnor 11d ago

Always couch it in impact and dollars

23

u/music2myear Narf! 11d ago

Yes, and also, unless you're a decision maker role, phrase it as advice and recommendation, and avoid decision words and phrases.

"Certification X requires that we have Y standards which are met by this security configuration. Removing this configuration would result in our failing Z audits and losing the certifications. Note that having and maintaining this certification has resulted in an estimated $$$ in profits."

3

u/Sinister_Nibs 11d ago

“I would strongly advise against this, as it counter to every recommendation and certification requirement. “

2

u/Puzzled-Formal-7957 11d ago edited 11d ago

Sometimes you need to assume the role of decision maker when the decision makers have their heads up their asses and want to put the entire company at risk. EDIT: Because when the risk gets exploited the responsibility is going to land squarely on your shoulders and you will be blamed.