Google Sign on for NXT users

Options

We have a database that we provide read access to our remote locations. Our policy has been that they must have a domain specific email address for us to authorize access (not a gmail, yahoo, etc account) in an effort to provide an extra layer of security. With Blackbaud's new offering of allowing users to sign in with a Google or Apple account, we are trying to review our policy. We have a handful of users who have refused to use a personal cell to receive authorization codes for MFA so this may be an alternative, but I am reticent to allow authorization through a third party. We operate in a rural area and many of these end users are of an older generation that does not automatically have a cell phone readily available. What kinds of policies have your organizations implemented to insure security and the ability for users like those above to have access?

Comments

  • Aldera Chisholm 2
    Aldera Chisholm 2 ✭✭✭✭✭
    Sixth Anniversary Facilitator 2 Name Dropper Photogenic

    @Kelly Lauster Hi Kelly, I don't have a written policy on this, but I have worked with volunteers in a similar way. Rather than have them use their personal email account, we created specific Google email accounts for our volunteers which we managed, and they used that account to login, not their personal account. While it's not a perfect solution, it does let them use the Google SSO. We also had volunteers for whom a mobile authentication wasn't a feasible solution.

Categories