ZTNA administration separation of duty options
search cancel

ZTNA administration separation of duty options

book

Article ID: 443132

calendar_today

Updated On:

Products

Symantec ZTNA

Issue/Introduction

Microsoft Entra role groups are used to differentiate ZTNA admins with users granted different tenant roles (one for admin and one for viewer).
Local administrator accounts maintained as a 'break-glass' fallback in case of Entra connectivity issues. 
Primary security concern is the vulnerability of these local accounts: they are currently linked to standard email addresses. If an attacker identifies a local admin username and compromises the associated email, they could initiate a password reset and gain full ZTNA administrative rights. 
What are the recommended ways to harden these 'break-glass' accounts using existing tools?
 

Environment

ZTNA.

Separation of duty for administration.

 

Resolution

Use MFA functionality for locally created ZTNA administrators, but send the code to another administrators mobile device using the following steps:

  • Enable MFA for a local admin on ZTNA Portal and enabled Symantec VIP
  • Created a local admin admin1 and admin2
  • Install Symantec VIP application on mobile devices of ZTNA admin1 and admin2
  • When logging in as admin1, share screen and have admin2 scan QR code (or register manually by providing the SYMC details); do the same process for admin2.

When admin1 logs in, admin2 is challenged for the VIP token and admin1 will get on when accepted.