momius - Fotolia
Multifactor authentication adds an extra layer of security to verify a user's identity, including in the public cloud. While it has its advantages, there can be management challenges, including synchronizing accounts and devices.
When cloud admins first configure multifactor authentication (MFA) for users, MFA devices are loosely related to users' cloud provider accounts. Admins generally enter the device's serial number, along with the first one or two resulting authentication codes produced by the device to initially synchronize the account and device.
However, there is no direct link between MFA devices and the public cloud provider or user account, so MFA devices can potentially fall out of synchronization. This happens if the device is reset or false key presses occur that produce subsequent authentication codes that are never used. If the authentication code falls out of sync, the user cannot log on to the cloud provider account until the MFA is restored.
Cloud providers offer ways to resynchronize MFA devices. Platforms like Amazon Web Services (AWS), for example, use an identity and access management (IAM) service to prompt users to resynchronize an MFA device that no longer provides the expected code sequence. Administrators can then use the AWS IAM console to locate and select the user that needs to be resynchronized, navigate to the Security Credentials tab and select Manage MFA Device. When the MFA wizard starts, select Resynchronize MFA device, and then enter the next two authentication codes produced by the device. When the process is complete, the user should be able to log on to AWS. Resynchronizations can also be initiated through the AWS command-line interface, Windows PowerShell and AWS IAM APIs.
Other public cloud platforms, such as Azure and Google, stress application-based MFA using smartphones to receive authentication messages or codes. In this case, the smartphone typically does not fall out of synchronization because it is receiving its authentication code from an authentication server, rather than simply generating its own code according to an independent algorithm.
MFA devices are not perfect; they can occasionally become lost or require replacement. Unfortunately, admins can only assign one MFA device to a user at a time, so there is no allowance for spare or backup MFA devices. When you must replace an MFA device, use the cloud provider's management console to deactivate the old device first, and then enable a new MFA device for that user according to the cloud provider's documentation.
Compare multifactor authentication products
Are you up to date on authentication methods?
Explore two-factor authentication options
Dig Deeper on Cloud security tools
Related Q&A from Stephen J. Bigelow
Application load balancers and API gateways both manage network traffic, but in their own ways. Learn the differences between them and how to use ... Continue Reading
Developers don't have a lot of free time. Code reuse helps dev teams focus on the most value aspects of a project, so ensure everyone knows how to ... Continue Reading
Although there are a handful of tools to help run Firecracker more easily, admins might find issues with the lack of major tool integration for the ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.