I've joked about writing an app on my phone that would just auto-respond to all the 2FA prompts with my PIN, and have been told that other people actually tried to (or did) implement such an application.
Meanwhile I was at a Googler's place a year ago and watched him tap a U2F device on the side of his laptop to complete the second factor. Sigh.
If your payroll system has a web interface, you can have an applicative firewall in front replay your stored credentials as a hacky SSO (after checking your identity another way, of course).
And Kerebos does nothing for these 2FA woes sadly.
I just bought one the other day for personal use, pretty cheap, cant say more becuase I have yet to receive it, but I have high hopes.
For at least 2 linux boxes I use, I needed to add udev rules for the yubikey. That wasn't immediately obvious and took a few minutes to figure out why it wasn't working.
You mean you work there and accessing services or tools requires you to do 2FA every time?
I hope they are already planning to overhaul that because it does seem like a very cumbersome and insecure way of "securing" accesses.
Could you explain more what you mean by this? Presumably it's not typing a phone into a PIN...?
Instead, MS's 2FA send a notification to your phone where you type in a static, pre-defined PIN. There is no way of knowing what actor or application triggered the 2FA request.
Okta at least shows which app is requesting permission.