checkly / public-roadmap

Checkly public roadmap. All planned features, updates and tweaks.
https://checklyhq.com
37 stars 7 forks source link

Add MFA - multi-factor authentication #77

Open ryanchapman opened 4 years ago

ryanchapman commented 4 years ago

Is your feature request related to a problem? Please describe. We're concerned about rogue actors accessing our Checkly account.

Describe the solution you'd like Add some form of MFA. Ideally, when I log in, Checkly asks me to enter a number generated by an app like Google Authenticator. On first login, Checkly would force the setup of MFA (if enforcement was enabled on our account by one of our Checkly admins).

Describe alternatives you've considered I thought about ways to make Google G Suite enforce MFA for third party sign ins, but couldn't figure out a way to do that. In that case, we'd need a way to only allow Google logins on the Checkly sign in page (disable GitHub and Checkly username/password).

Additional context The company I work for is a healthcare company. They are frequently asked by customers if third party service providers enforce MFA. So it's both a security and compliance issue for that company.

tnolet commented 3 years ago

@ryanchapman thanks for reporting this. We do not have this on a short term roadmap, but we will have a look at auth0 our authentication provider.