0
Pending Review

Password protect Backstage and Administrative Command Prompt

Adam - CAPS Net Admin 3 days ago 0

   Backstage and the administrative Command Prompt provide administrative level access to systems and endpoints that would otherwise require credentials and in most cases MFA in our environment. Currently access to ScreenConnect and thereby these two features, a threat-actor circumvents all of our hardening we have implemented with MFA and the requirement of long complex passwords.

   Ideally I would love to see Backstage require standard authentication to the system being accessed to be utilized. At the very least, the requirement of a system password in ScreenConnect that is only accessible to an Admin account to utilize Backstage and the Administrative Command Prompt would be a significant security enhancement and would make me sleep better at night.