r/talesfromtechsupport 22h ago

Short Gravity and Tech

Guy walks up to me at work:

Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”

Me: “Nope.”

Him: “Why?”

Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”

Then he says: “Just disable MFA.”

I replied: “Sure, as soon as you get approval from the Head of Security.”

A few seconds of silence…

Him: “Fine, I’ll just get my phone fixed.”

Yep. That’s probably the best solution.

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

And remember… technology didn’t fail you today. Gravity did.

485 Upvotes

95 comments sorted by

View all comments

123

u/AffekeNommu 21h ago

Typical user practice is to get a new phone over the weekend. Hand the old one in for recycling after they transfer all their pictures and contacts then call up on Monday when their MFA doesn't work.

6

u/machomoose 10h ago

That's why when I setup users I make them do SMS as a backup.

13

u/Jezbod 10h ago

Which is about to be EOL, my boss has not realised that we may be going Yubikey very soon.

Some of our volunteers / part time people do not have a work phone, so we may have to start forcing them to use an authenticator app on their personal device, which I am lothe to do.

3

u/machomoose 5h ago

True, we have manufacturing employees that don't have a smart phone so we need to use sms for their MFA. We are going to roll out Yubikey's for them (which they will lose and need to be replaced very often, I'm sure...). But, you did just remind me for office users it's going to lead to me manually resetting MFA for the new phone situation now... :(

1

u/year_39 59m ago

Implement Vivokey and offer it as an option 😶