Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Automate GR 1 and 2 MFA evidence collection via IdP API calls #97

Open
fmichaelobrien opened this issue Nov 25, 2022 · 0 comments
Open
Labels
enhancement New feature or request

Comments

@fmichaelobrien
Copy link
Contributor

Unfortunately GR 1, 2 are tricky and fully manual (not part of the guardrails code yet) - but they can be via Workspace API calls (like GCP Asset Inventory calls for services)
Yes, these are usually via the federated IdP (azure ad for example or directly in Workspace) but for now the check is manual - verify MFA on the break glass accounts and MFA on the org is set via screen caps

any change/updates to this we should put in our evidence collection doc
https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-security-controls.md#01-protect-root--global-admins-account

or directly on the GR notes (1-2 weeks propagation time)
https://github.com/canada-ca/cloud-guardrails/blob/master/EN/01_Protect-Root-Account.md

@fmichaelobrien fmichaelobrien added the enhancement New feature or request label Nov 25, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant