Bypassing FortiAuthenticator
Hi,
For context, I'm not "fresh" to sysadmin, but I am "very fresh" to all things Forti-*. I'm a month or two into a new gig with an MSP that has FortiGate and FortiAuthenticator deployments sprinked around their (our, I guess) clients.
Chatting with a previous engineer that had a hand in setting it all up, recently, he commented that he couldn't really see the point of mandating 2FA with FortiTokens since this doesn't solve the "rogue contractor with laptop" plugging in somewhere and authenticating to the file server with username and password, since it's at the point where users sign onto their laptop/desktop that has OTP authentication challenge, but if I pass credentials for a standard user to a file server from a device that isn't running the updated msgina.dll, the file server (or other resource provider) happily hands over the requested assets.
I'm betting this is a "solved problem" but I haven't seen the suggested approach in the documents I've found to review, todate. Can someone send me a shortcut to where I find the "easy button" on this?
