MFA Enforcement for Local Users Following 26D, Impact on Non-Production Environments After P2T
Summary:
Hi all,
Oracle has advised that Multi-Factor Authentication (MFA) will become mandatory for interactive logins for local Fusion users that do not authenticate via an external Identity Provider (SSO/IdP).
Whilst we fully support the security benefits of MFA, we're struggling to understand how this is expected to work in non-production environments following a Production-to-Test (P2T) refresh where data masking is enabled.
In our case, after P2T:
- Email addresses are masked.
- Telephone numbers are masked.
- Local users in non-production environments therefore no longer have access to the registered MFA factors copied from production.
- It may not be practical or desirable to maintain real email addresses and telephone numbers in non-production environments purely to support MFA registration and authentication.
Tagged:
2