Add option for app-based 2FA for Work from Home (instead of only via SMS)
2FA Authenticator app for work from home instead of just 2FA via SMS
Right now, work from home only facilitates 2FA through the use of SMS. It would be nice to see the option to enable 2FA through the use of a 2FA app such as Duo, Authy, Google Authenticator, etc. This functionality is already available for technician accounts.
Technically, 2FA via SMS is the least secure method of doing 2FA and it has been demonstrated that a sufficiently skilled hacker can intercept the text messages that contain 2FA codes. For this reason, app-based 2FA is preferrable over SMS-based 2FA.
SMS-based 2FA is still desirable to some people, so it is probably useful to keep it as an option, but having an option to use app-based 2FA would be appropriate from a standpoint of security posture.
-
Mark Perrin commented
Need to be able to choose whether MFA is sent via SMS or Email.
We have users that travel and don't always have access to their normal phones for SMS (they get local SIM cards in the country they are in).
We need them to be able to login to Work From Home and the only way currently is via SMS. This needs to be a choice between SMS, Email, or MFA Application.