We currently use shared Role Identities as managed accounts to reduce the number of Admin accounts and as a way to enforce RBAC. As those accounts are not owned by specific users, they cannot be registered for MFA by individual users, and therefore the MFA requirement had to be disabled on the managed assets for the Role Identities, which is less secure (in case a Role ID is compromised) and against our policies.
We would very much like to see a feature added to Password Safe allowing it to respond to 3rd party MFA challenges automatically, when establishing privileged sessions with the shared Role Identities.
https://beyondtrust-public.ideas.aha.io/ideas/T2PSM-I-1808
Do you have similar situation by any chance? You can share your experience or vote for an idea if you find it useful.
Cheers,
Thanks & Regards,
Sathya