@cPanelLauren,
I agree that setting the shell to noshell is important and will do that.
Should I create a new thread for this question?
I want some information on two factor authentication. Using the Microsoft services, whenever we login, we have to grab a code off our cells using the Microsoft Authenticator app, which changes every 30 seconds. From a simple test, I was able to determine that cPanel / WHM supports this. But to what degree?
With the Microsoft stuff, if we don't have access to the cell phones, we can receive a verification phone call with the number we setup during our account creation (that we can change after we've successfully logged in) or receive a text message with a code. The phone call just has us press # to prove it's us. The text message provides a code.
Also, is there any way to set up the same two-factor authentication for SSH access, where if we do not enter the correct code, it refuses us access to system? I was thinking perhaps I could modify a login script in the various users directories and have it point to the script / binary file that cPanel uses for the 2-factor authentication...would this be possible? I guess this should be under a new topic, but not sure where to put it. Maybe under Security?
I agree that setting the shell to noshell is important and will do that.
Should I create a new thread for this question?
I want some information on two factor authentication. Using the Microsoft services, whenever we login, we have to grab a code off our cells using the Microsoft Authenticator app, which changes every 30 seconds. From a simple test, I was able to determine that cPanel / WHM supports this. But to what degree?
With the Microsoft stuff, if we don't have access to the cell phones, we can receive a verification phone call with the number we setup during our account creation (that we can change after we've successfully logged in) or receive a text message with a code. The phone call just has us press # to prove it's us. The text message provides a code.
Also, is there any way to set up the same two-factor authentication for SSH access, where if we do not enter the correct code, it refuses us access to system? I was thinking perhaps I could modify a login script in the various users directories and have it point to the script / binary file that cPanel uses for the 2-factor authentication...would this be possible? I guess this should be under a new topic, but not sure where to put it. Maybe under Security?