<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MFA for Administrators in Cloud Networking Platform</title>
    <link>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453750#M12460</link>
    <description>&lt;P&gt;Why cant you have another organization Administrator reset this?/ It seems a little overkill to have to create a case just for a new phone number or lost device. &lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2019 15:30:33 GMT</pubDate>
    <dc:creator>DillonWhite9048</dc:creator>
    <dc:date>2019-08-13T15:30:33Z</dc:date>
    <item>
      <title>MFA for Administrators</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453750#M12460</link>
      <description>&lt;P&gt;Why cant you have another organization Administrator reset this?/ It seems a little overkill to have to create a case just for a new phone number or lost device. &lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 15:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453750#M12460</guid>
      <dc:creator>DillonWhite9048</dc:creator>
      <dc:date>2019-08-13T15:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Administrators</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453751#M12461</link>
      <description>&lt;P&gt;Please note SMS auth is considered beta&lt;/P&gt;&lt;P&gt;Process to reset is outlined here.&lt;/P&gt;&lt;P&gt;&lt;A href="https://documentation.meraki.com/zGeneral_Administration/Other_Topics/Two-Factor_Authentication#Recovering_Access_to_Accounts_Protected_by_Two-Factor_Authentication" target="_blank" rel="nofollow noopener noreferrer"&gt;https://documentation.meraki.com/zGeneral_Administration/Other_Topics/Two-Factor_Authentication#Recovering_Access_to_Accounts_Protected_by_Two-Factor_Authentication&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I would say the general position is that losing devices isn't a regular thing. Allowing any admin to reset a 2FA could cause a security issue in that if the admin was a disgruntled employee then they could reset all the 2FA and it would break logins for everyone. They then could cause havoc. Essentially this process allows User, Admin, and Support to ok the change. Security is a pain, but required. My suggestion would be use a device you won't lose using Google Authenticator instead of SMS.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 16:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453751#M12461</guid>
      <dc:creator>SoCalRacer</dc:creator>
      <dc:date>2019-08-13T16:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Administrators</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453752#M12462</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/16460"&gt;@SoCalRacer&lt;/A&gt; Yeah I actually use DUO auth so it's not bad I just had a coworker have to factory reset his phone and the below happened. &lt;/P&gt;&lt;P&gt;"Google Auth App won't restore my settings " I look at the documentation for 2 minutes. Proceed to delete and readd admin&lt;/P&gt;&lt;P&gt;Told him to Use  SMS or DUO as we have an enterprise Duo and it saves all your settings&lt;/P&gt;&lt;P&gt;I'm all for security and that internal disgruntled worker makes sense. But even DUO doesn't require that for a forgotten device, hence my conundrum for this notarized security! &lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 16:17:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453752#M12462</guid>
      <dc:creator>DillonWhite9048</dc:creator>
      <dc:date>2019-08-13T16:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Administrators</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453753#M12463</link>
      <description>&lt;P&gt;We have all of our admin accounts across most services using MFA / 2FA. We do also have a backup account just in case without this enabled, the last thing I want is to be locked out becuase I am not recieving the notification.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2019 23:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453753#M12463</guid>
      <dc:creator>BlakeRichardson</dc:creator>
      <dc:date>2019-08-13T23:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for Administrators</title>
      <link>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453754#M12464</link>
      <description>&lt;P&gt;I am an admin in our dashboard, another user changed his cell phone and now he cannot &lt;SPAN&gt;authenticate or&lt;/SPAN&gt; access the dashboard and I cannot help him. I read the security concern. which I consider invalid. I am the Domain Admin, and it is part of my role to be able to reset, change, add, delete any account or application. You are taking my role. I appreciate the advice. Using your logic then, &lt;SPAN&gt;Allowing Cisco support admin to reset a 2FA could cause a security issue in that if the cisco admin was a disgruntled &lt;SPAN&gt;employee,&lt;/SPAN&gt; then they could reset all the 2FA and it would break logins for everyone in the cisco world. You could cause havoc. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 18:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-networking-platform/mfa-for-administrators/m-p/5453754#M12464</guid>
      <dc:creator>MarioBlandino</dc:creator>
      <dc:date>2023-02-27T18:56:56Z</dc:date>
    </item>
  </channel>
</rss>

