Skip to content

Policy: Autolock + Require Password #375

@erickufrin-okta

Description

@erickufrin-okta

Allow for centralized policy control of certain settings + enforcement of password.

  • enforce autolock after X-num min (for flexibility it should allow for X-number of minutes vs pre-defined increments)
  • enforce autolock on startup (upon launch of a new chrome tab, the OTP's should be locked)
  • enforce password be set (dont allow enrolling OTP tokens without a password set first)

Without these features it is easy for someone to access OTP codes on an unlocked workstation.

For things which may only require an OTP code, by having a password to unlock the Authenticator extension gives us an additional "factor" of "something known" as well as "something I have" being the enrolled OTP extension itself.

While having optional features to autolock and passwords is great, we need to have a way to make them mandatory by policy and push via normal management channels.

The 3 ways we apply policy to Chrome extensions are:

  • Windows Group Policy
  • macOS JAMF
  • ChromeOS cPanel

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions