Windows 2FA – It’s a Big “Where” In “Everywhere”

If you’re a regular reader of our blog, you’ll know that here at Centrify, we’re big believers in multi-factor authentication (MFA) and strong supporters of MFA Everywhere. Passwords don’t protect us, our data or our businesses – and we need something better. As an extension of our commitment to eradicate passwords wherever possible, and bolster security with MFA wherever we can, we’ve extended our “MFA Everywhere” initiative with a key new “where” – 2FA for Windows logon. Speed and Security We can hear the cries now: “2FA! Windows Logon! Won’t that slow all my users down?” Not if the second…

Secure Windows Administration and Eliminate Dual Active Directory Accounts for Administrators

I’ve seen many environments lately where the Windows administrators have two Active Directory accounts, one that they use for their normal end user activities, such as reading email, and the other they use for any administrative duty. This creates several very real problems: a) the admin now has two different accounts with a password that he must now maintain over time, probably not a huge problem but just a pain for the admin; b) you still have to trust the admin where he will use the second admin account and hope that he doesn’t use it for normal daily activity…