2FA? We've heard of it: White hats weirded out by lack of account security in enterprise


I can understand folks not wanting to use their own phones for work generally - i.e. calls etc - but for 2FA I'd prefer not to have to carry an extra device of any kind. But that's just me.

My own O365 and Azure (via MAPS) admin accounts use 2FA.

My lab servers are set up to email me if anyone logs onto them/unlocks them. That works for me as I should be the only person logging on. Anyone else would mean the machine is compromised.

Really don't understand why places don't use MFA at least for privileged accounts

