Google Cloud to make MFA mandatory by the end of 2025

Google Cloud to make MFA mandatory by the end of 2025

November 5, 2024 at 03:13PM

Google will mandate multi-factor authentication (MFA) for all Google Cloud accounts by the end of 2025 to improve security. The rollout will occur in three phases, starting with reminders for non-MFA users. Research indicates MFA significantly reduces hacking risks, and Google offers user-friendly options for implementation.

### Meeting Takeaways on Google Cloud Multi-Factor Authentication (MFA) Implementation:

1. **Mandatory MFA Announcement**: Google has announced that multi-factor authentication will be mandatory for all Google Cloud accounts by the end of 2025 to enhance security.

2. **Impact Scope**: The MFA requirement will affect all users and administrators of Google Cloud services but will not apply to general consumer Google accounts.

3. **Phased Rollout Plan**:
– **Phase 1** (Starting this month): Users without MFA will receive reminders on their console screens. Approximately 30% of Cloud users fall into this category.
– **Phase 2** (Early 2025): Existing and new users who log in using only a password will receive notifications to enable MFA across various Google Cloud platforms.
– **Phase 3** (End of 2025): MFA will be mandatory for all users, including federated users, who can utilize their identity provider’s MFA or add Google’s MFA.

4. **Transition Support**: Google Cloud will provide advance notices to enterprises and users to help with the transition to mandatory MFA.

5. **Security Assertion**: Research from CISA indicates that users with MFA are 99% less likely to be hacked, a statistic that Google supports with its own data.

6. **User-Friendly Options**: Google is promoting user-friendly MFA options like passkeys, utilizing biometric data for security and convenience, aiming to minimize disruption during the adoption phase.

7. **MFA Setup Instructions**:
– To enable MFA, users should visit ‘security.google.com,’ select ‘2-Step Verification’ under “How you sign in to Google,” and follow the instructions.
– Users of Cloud Identity-managed accounts who cannot access the ‘2-Step Verification’ option may be facing admin restrictions.

8. **Further Guidance**: For comprehensive instructions on setting up MFA, users are directed to refer to Google’s official guide.

#### Conclusion:
The transition to mandatory MFA is a critical security measure designed to protect Google Cloud accounts from evolving cyber threats, and Google is committed to facilitating a smooth implementation process for its users.

Full Article

By proceeding you understand and give your consent that your IP address and browser information might be processed by the security plugins installed on this site.
×