6 hours ago · 8 min read1696 words · Tech · hide · 0 comments

Consider a client who wants multi-factor authentication turned off because the extra prompts are getting in the way of work. The complaint deserves attention. The requested fix deserves scrutiny.Something may be wrong with the setup. A session policy may be too aggressive, a device may not be registered correctly, or the chosen authentication method may be a poor fit for the people using it. Those are problems an IT provider should investigate. Disabling the protection across the business because someone is tired of it would leave a different problem behind.This is where an MSP has to be willing to disagree with the person paying the invoice.Gary Pica makes that case in The customer is wrong, arguing that managed service providers have an obligation to push back when clients make poor security decisions. I agree with that central point.A business hires an MSP partly for its judgment. If the provider abandons that judgment whenever a recommendation becomes inconvenient, the client is…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.