New unified What We're Working On
Glad to see these on a WWWO post for SAM, these align with the features we are needing for many of out elevated privilege systems. Thank you
Any plans allow 3rd party 2factor auth like Symantec VIP?
Hi, My infosec is asking to include captcha on login page if I need to access the website on internet, please add this in your roadmap.
Just curious, what is the use case for making such a sensitive system accessible publicly on the internet? If you do, a CAPTCHA won't do very much to protect you from malicious actors who want to break in. I would highly suggest using a web application firewall and a reverse proxy to protect access to Orion. In your reverse proxy, use one that allows you to inject a login page with ties to MFA (multi-factor authentication). This will offer far more protection than a CAPTCHA, and would also separate attackers from the actual IIS attack surface.
sturdyerde Can you elaborate on this recommendation a bit more? I'm not terribly familiar with reverse proxies, but I know our infrastructure team is implementing MFA in front of things like our Office 365 and our VPN. I'd love to increase the security of our Orion instance to allow it to be internet facing.
A reverse proxy can sometimes include web application firewall functionality (such as Citrix Netscaler / ADC). They can also add MFA at the point of reverse proxy, which puts the security closer to the edge, and can potentially stop malicious traffic before it even gets to your Orion login page.
SolarWinds solutions are rooted in our deep connection to our user base in the THWACK© online community. More than 180,000 members are here to solve problems, share technology and best practices, and directly contribute to our product development process.