Salta al contenuto principale

Two-factor authentication

Thread needs solution

In order to access the data stored in the cloud, a login with a user name and password is sufficient. I don't feel this is up to date, especially in view of the fact that Acronis is committed to security. I would like to see an implementation of an (optional) second factor for Acronis Cyber Protect Home Office when logging in.

0 Users found this helpful
frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Messaggi: 2
Commenti: 1727

Hello Thomas,

As I mentioned in our previous conversation, I have informed the team about your feature request.

However, we currently do not have an estimated time for implementation.

Thank you in advance.

I too would like to vote for this and would add a few things:

1. FIDO/FIDO2 support would be welcomed. I think FIDO/FIDO2 makes the most sense for backup software/services like Acronis because the recommended practice with FIDO(2) is for individuals to have two keys - one always with them, and another in a safe location in case of loss/theft/failure/damage. 

2. TOTP support should be allowed with MULTIPLE authenticators. By this I mean allow users/accounts to generate at least two authenticators/secrets (QR codes) so they can say, setup phone #1 with a unique secret and phone #2 with a unique secret. This is a mitigation against disaster (fire/theft) risks.

3. MFA "tokens" should be subject to regular review by users (once every 1-2 years) for validation that they are still functional and not expired (i.e. old phone replaced, FIDO token lost/damaged).

4. MFA should be mandatory - not optional, so long as users can do a "nuclear" reset of their account via email.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Messaggi: 2
Commenti: 1727

JAMES wrote:

I too would like to vote for this and would add a few things:

1. FIDO/FIDO2 support would be welcomed. I think FIDO/FIDO2 makes the most sense for backup software/services like Acronis because the recommended practice with FIDO(2) is for individuals to have two keys - one always with them, and another in a safe location in case of loss/theft/failure/damage. 

2. TOTP support should be allowed with MULTIPLE authenticators. By this I mean allow users/accounts to generate at least two authenticators/secrets (QR codes) so they can say, setup phone #1 with a unique secret and phone #2 with a unique secret. This is a mitigation against disaster (fire/theft) risks.

3. MFA "tokens" should be subject to regular review by users (once every 1-2 years) for validation that they are still functional and not expired (i.e. old phone replaced, FIDO token lost/damaged).

4. MFA should be mandatory - not optional, so long as users can do a "nuclear" reset of their account via email.

Hello James,

I received your feature request with the code TI-131874.

I have forwarded your message and suggestions to the team.

As of now, there is no ETA for the implementation of the feature.

Please feel free to update the thread or participate in the forum whenever you need.

Thanks in advance!