For our business we use a number of different apps and websites but only two of them offer 2FA with a security key. The rest allow for an authenticator app. In this case, it seems just using an authenticator app would be best for consistency and without needing to purchase keys.

Of course, installing authenticatior apps on each device would be a no-no since it wouldn’t technically be 2FA. Then do we use each employee’s personal phones? Not sure how to proceed.

  • FriedSinkOP
    link
    fedilink
    arrow-up
    3
    ·
    5 months ago

    What about using a password manager to store 2FAs for apps and websites and then a security key for the password manager 2FA?

    • cron@feddit.de
      link
      fedilink
      English
      arrow-up
      4
      ·
      5 months ago

      I’m not too happy with this solution. Not extremely bad, but technically, both password and the second factor are stored in the same place, which makes this similar in security to just using a long, random password with a password manager.