
Multifactor Authentication Service on Azure for DTEK
Implementing a cloud-based MFA for Ukraine’s largest energy holding company
Business Challenge
As many companies try to maintain business resilience in the times of COVID-19, they have to make adjustments during the period of extreme disruption and react to that situation. A large corporation, DTEK, is not an exception. The organization wanted to strengthen authentication to IT services, especially considering the pandemic and the need for employees to work remotely. To lower the likelihood of security incidents, we considered two solutions: Azure AD Multi-Factor Authentication and passwordless login. The two proposed scenarios would meet the client’s security requirements, allowing for different levels of access for different employee roles. Depending on the scenario, the client’s associates would be able to use either MFA or passwordless login or even both technologies in one single scenario.
Furthermore, not all applications had MFA support and direct integration with Azure AD. We tested a number of options and found a possibility to integrate various types and application classes under one roof. Besides, we needed to find a fitting key solution so that our client could satisfy all the security requirements for both MFA and passwordless authentication. Finally, taking into account the restrictions introduced by the pandemic in 2020, the joint delivery team had to figure out how to realize the whole project scope without meeting face-to-face.
Solution
It was essential for DTEK that their admins would not have to use any passwords in the remote admin scenario. Password hashes can be easily compromised by malicious parties – and with admin rights, they would have full access to any IT system. Therefore, after conducting comprehensive research on the market, we came up with the solution to utilize token keys.
Furthermore, using keys or MFA, access to the following components of IT infrastructure becomes easy for admins and users:
- Windows Hello for Business
- Office 365 apps
- The applications supporting MFA and allowing integration with Azure AD
Additionally, the associates would need to access a number of IT services with MFA: Microsoft 365, business applications (SAP, Salesforce), and on-premises applications in virtualized infrastructure. We suggested using FIDO2 tokens for access to M365 consoles and admin portals as well as configuring a number of components to guarantee the smooth performance of Windows Hello for Business.
Together with our client, we took a comprehensive approach and came up with the following solutions to meet the customer’s requirements:
- Increased security level of accounts. When working remotely, associates connect to the customer’s IT services outside of the controlled environment. Thus, the protection of accounts, especially privileged ones, became a pressing matter for DTEK that it tackled with our help.
- Implemented conditional access. Now, the client can control scenarios that might or might not require two-step authentication, for instance, when an authentication request comes from a controlled network segment.
- Access Log for better analytics. The client can view who accessed the system using two-factor authentication and analyze this data.
- Extended MFA functionality. In addition to using off-the-shelf MFA configuration, the client can now also connect cloud applications, which can be integrated with Azure AD and on-premises applications depending on the authentication scenario.
- Offered a multi-layered protection mechanism to privileged account owners.
- Realized MFA and passwordless authentication in hybrid applications that the client has today and secured an opportunity to apply these methods with new applications in the future.
- Leveled up identity protection, creating a solid foundation to upscale security across the whole IT landscape.
- Created a set of tech documentation that supports the main project deliverables:
- Solution architecture
- Service passport
- User guide
- Admin guide.
- Conducted onboarding sessions and knowledge transfer workshops to introduce users to the implemented system.
As a result of our collaboration with our partner, DTEK implemented a solution for user authentication and secure access to information resources and the company’s infrastructure. In addition, we lowered the risks of unauthorized access. We have grown the technical expertise of our in-house team in administration, access policies setup, and Microsoft Azure MFA service monitoring.
- Oleksii Morozov, Head of system infrastructure at IT Infrastructure department, DTEK
Technologies & Tools
- FIDO2 keys
- Microsoft 365
- Microsoft Azure AD
- ADDS
- AD FS
- NPS
- ADCS (PKI)
Azure AD services:
- MFA
- SSPR
- Apps and Apps Proxy
- Conditional Access
- Identity Protection
Business Value
We helped DTEK address a number of security challenges. The joint tech team created a powerful multifold authentication system, allowing our client to set up the necessary access levels for varied roles of users.
Within 6 months, through the joint efforts of the two expert teams, we successfully orchestrated the project delivery and accounted for all the associated risks, which allowed our client to smoothly upgrade the security of their IT services:
- Adoption of recommended information security measures in line with existing industry standards for user authentication
- Increased identity protection without security trade-offs
- Identity and asset theft prevention
- Improved another aspect of collaboration with IT assets through a fully-fledged user authentication solution.
Business IT security is one of the most important parts of running a modern company. At DTEK, we cannot afford to lose sensitive information, compromise access to the company’s important files, or decrease employee productivity. With the help of our partner’s team, we implemented modern technical solutions, including Azure AD Multi-Factor Authentication and passwordless login, taking our security to the next level. It’s a win-win for our IT security team, our employees, our company, and our clients at large.
- Dmytro Osyka, CIO, DTEK