Don’t be “THAT” Guy Vol.1: Keep Complex Credentials

Pierre_3CX

Staff member
3CX Support
Joined
Aug 1, 2013
Messages
781
Reaction score
401
Our recent blog post “3CX Global IP Blacklist: Security By Default” highlighted the importance that we place on security and how we endeavor to combat call fraud and hacking schemes. We finished it up advising to keep an eye out for some more specifics, stats, and patterns. Well, here it is. Over a series of 4 blog posts, we will raise awarenes...
Continue reading the Original Blog Post.
 
MFA would be a great security addition...

I know SSO, but that's not for everyone. MFA is becoming a must.
 
+1 for MFA. Also having multiple logins would be useful from an MSP point of view. An audit log isn't as much use when all the changes are made by one 'user'
 
  • Love
Reactions: HLM 3CX
Hello,
As you mentioned MFA is already possible using the SSO feature along with a Google or MS account and using their Authenticator app or SMS. But feel free to vote for changes or post your feature requests on 3CX Ideas: https://www.3cx.com/ideas

In regards to the Audit logs note that it includes also the source IP address along with username.
 
I rather mean native 2FA for remote administrators. The Audit log does show the source IP, but when the system is locked down to a Public IP, and people use a VPN to access the system, the same IP is in use each time.

As an MSP imagine that 10 people have access to this phone system in order to manage / make changes for the customer. All 10 people are using 1 login, so there is no record of who made what change built in.

Furthermore should an employee leave, credentials would need changing rather than the user being removed.
 
  • Love
Reactions: HLM 3CX
The "Audit" log need to be fixed to properly capture changes.

It needs to show "who" made the change - right now delegated O365 admins still show up as the main admin account in the logs.
 
It needs to show "who" made the change - right now delegated O365 admins still show up as the main admin account in the logs.
That's actually expected as, in reality, they are logging in as the main admin. If you do not want this to be the case I recommend providing these extensions with Management Console Access from the "Users >> Edit >> Rights" section instead.
 
That's actually expected as, in reality, they are logging in as the main admin. If you do not want this to be the case I recommend providing these extensions with Management Console Access from the "Users >> Edit >> Rights" section instead.
I appreciate the suggestion - but as P4ul mentioned in post (#3, #5) in an environment where we manage a large number of 3CX instances, manually creating a user account for an employee, or multiple employees for that case becomes a management nightmare.

For example - if I have 30 instances I need to create 30 use accounts besides if I want someone else to manage that box.
Now take that example and multiply 30 instances times 5 employees, who will be managing this.

I now have to create a total of 150 user accounts across 30 servers. God forbid if one of those employees is let go. I now have to go back and touch 30 servers again, in order to delete the account for that user.

The whole idea of integrating with O365 and allowing "delegated" Admin access goes away if that simple "Audit" log feature cannot properly track who made the changes.

Please remember that IP addresses can be shared and are not uniquely identified. Leveraging that information in the Audit log does not really solve a problem.
 

Forum statistics

Threads
111,974
Messages
590,083
Members
164,900
Latest member
Silent_Guru