Skip to content

Commit 823b07f

Browse files
authored
Merge pull request #1 from google-admin/2fa
Add 2FA message.
2 parents 9584fd8 + fc3e2a3 commit 823b07f

File tree

1 file changed

+35
-0
lines changed

1 file changed

+35
-0
lines changed

20250530.md

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,35 @@
1+
# Enforcing Secure 2FA Across the Alphabet Enterprise
2+
3+
As part of our ongoing efforts to secure Alphabet's source code, on June 30th 2025, we will **require all users accessing Alphabet-owned GitHub Organizations use only secure MFA methods**.
4+
5+
Secure methods include the following:
6+
* Authenticator Apps (TOTP)
7+
* Passkeys
8+
* Security Keys
9+
* GitHub Mobile App (acting as 2fa)
10+
11+
12+
Insecure methods include the following:
13+
* SMS
14+
15+
## What will happen after this change?
16+
Users will receive an email from GitHub notifying them of this change.
17+
Users will be immediately locked out from accessing organization resources and will be prompted to set up a secure method or remove insecure methods. Once this is complete, access is immediately restored.
18+
19+
> [!NOTE]
20+
> This will also impact external collaborators and non-Googler members of Alphabet-owned Organizations.
21+
22+
## What should I do ahead of time?
23+
We strongly recommend reviewing your MFA methods ahead of this change to ensure that:
24+
25+
1. You have at least one secure method
26+
1. (Remove SMS as a 2FA method)[https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa/changing-your-two-factor-authentication-method]
27+
28+
> [!NOTE]
29+
> You must add an Authenticator App prior to GitHub permitting the removal of an SMS based authentication method
30+
31+
## What is the rollout plan?
32+
1. Shortly after sending this email, there will be a butter bar added to notify users of the changes in GitHub
33+
1. We will send reminder emails notifying users of this change (2 and 1 week prior to enforcement)
34+
1. We will begin a phased roll out on June 30th, 2025 to gather initial feedback
35+
1. Pending the success of 3, we’ll aim to rollout to all Organizations by July 14th, 2025

0 commit comments

Comments
 (0)