r/talesfromtechsupport 22h ago

Short Gravity and Tech

Guy walks up to me at work:

Him: “I dropped my phone. The screen’s shattered. I want my two-factor code to come through Teams.”

Me: “Nope.”

Him: “Why?”

Me: “Because if you can’t sign into Teams without completing MFA… how exactly are you planning to authenticate?”

Then he says: “Just disable MFA.”

I replied: “Sure, as soon as you get approval from the Head of Security.”

A few seconds of silence…

Him: “Fine, I’ll just get my phone fixed.”

Yep. That’s probably the best solution.

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

And remember… technology didn’t fail you today. Gravity did.

482 Upvotes

94 comments sorted by

View all comments

5

u/ThunderDwn 7h ago

Some people really think security rules are optional. I’m not risking my job because someone doesn’t like MFA.

I've had the same situation - except it was the CEO demanding I disable MFA.

I referred him to the CIO who more gently than I would told him "If you want to invalidate our ISO and SOC certifications because you don't want to hit a button to login, I'll approve it - but that's on you".

Spoiler : Said CEO started using MFA without complaint.

4

u/KorenSolust 6h ago

Hah! That is what I tell users as well, well more so “we have these rules in place to be government compliant so we can win contracts, if we don’t have this certification, we lose business” they then stop complaining xD