Hi I am a bit newer to the defectdojo community so forgive me if this has been noted elsewhere, but are there any plans to support MFA in v3 of the community edition of defect dojo in light of the deprecation of SSO?
Hi callard, thanks for raising this. MFA will remain a DefectDojo Pro feature and isn't planned for the Community edition. The main reason is that reliably testing and maintaining authentication features across a wide range of configurations is difficult for an open source project to sustain. Keeping MFA in Pro lets us guarantee proper test coverage and confidently ship releases without regressions in authentication flows. We appreciate the input, and we'll keep the feedback in mind as the roadmap continues to evolve.
At the moment then our only ideas for mitigating controls would be to put it in an isolated environment with a tunneled connection such as Cloudflare ztna or simply whitelisting our office public IP. Let me know if there are any other suggestions for features on the platform itself that might be helpful should you be aware of any. Currently we have an instance in AWS and we access the host over the public IP so there is some amount of exposure. This is the case to help ease integration from various platforms we manage

