- No SSO
- No way to enforce MFA, restrict logins to trusted devices and IPs, etc...
- No message / audit logs
I like discord for personal use, no way I would use it professionally
Give new users a very short window, or not able to use until their hardware key, phone enclave, etc is registered for MFA.
You could even go as far as to send pre-registered hardware keys by mail, or have them picked up from HQ upon hire.
Certainly would have solved some of the recent "who actually works in infra at Twitter" debacle, now that I'm thinking about it.
Give new users a very short window, or not able to use until their hardware key, phone enclave, etc is registered for MFA.
You could even go as far as to send pre-registered hardware keys by mail, or have them picked up from HQ upon hire.
Certainly would have solved some of the recent "who actually works in infra at Twitter" debacle, now that I'm thinking about it.