Device protection using configuration lockdown mode
Techniques are provided for device protection using a configuration lockdown mode. One method comprises receiving a configuration command from a user for a device; determining, responsive to receiving the configuration command, if the device is in a configuration lockdown mode that limits an execution of one or more configuration commands; and performing one or more automated remedial actions in response to determining that the device is in the configuration lockdown mode, such as generating a configuration lockdown alert. A configuration manager associated with the device may (i) determine if a duration of a disabling of the configuration lockdown mode violates one or more duration limits, and/or (ii) determine if the device is in the configuration lockdown mode.
1. A method, comprising:
receiving a configuration command from a user to modify a configuration of at least a portion of a device;
in response to receiving the configuration command, performing the following steps:
determining whether the device is in a configuration lockdown mode that limits an execution of one or more configuration commands, wherein the received configuration command is distinct from a command to enable the configuration lockdown mode, wherein a duration of a disabling of the configuration lockdown mode is limited by one or more duration limits;
executing the received configuration command in response to determining that the device is not in the configuration lockdown mode and that the one or more duration limits are not violated; and
performing one or more automated actions and rejecting the received configuration command in response to determining that the device is in the configuration lockdown mode;
wherein the method is performed by at least one processing device comprising a processor coupled to a memory.
2. The method of claim 1 , further comprising querying a configuration manager associated with the device to obtain the one or more duration limits for the configuration lockdown mode.
3. The method of claim 1 , further comprising determining, by a configuration manager associated with the device, if the device is in the configuration lockdown mode.
4. The method of claim 1 , wherein the one or more automated actions comprise one or more of generating a configuration lockdown alert and disabling the device.
5. The method of claim 1 , wherein the configuration lockdown mode is selectively enabled and disabled.
6. The method of claim 2 , further comprising evaluating credentials of the user.
7. The method of claim 1 , further comprising evaluating permissions of the user to execute the configuration command.
8. An apparatus comprising:
at least one processing device comprising a processor coupled to a memory;
the at least one processing device being configured to implement the following steps:
receiving a configuration command from a user to modify a configuration of at least a portion of a device;
in response to receiving the configuration command, performing the following steps:
determining whether the device is in a configuration lockdown mode that limits an execution of one or more configuration commands, wherein the received configuration command is distinct from a command to enable the configuration lockdown mode, wherein a duration of a disabling of the configuration lockdown mode is limited by one or more duration limits;
executing the received configuration command in response to determining that the device is not in the configuration lockdown mode and that the one or more duration limits are not violated; and
performing one or more automated actions and rejecting the received configuration command in response to determining that the device is in the configuration lockdown mode.
9. The apparatus of claim 8 , further comprising querying a configuration manager associated with the device to obtain the one or more duration limits for the configuration lockdown mode.
10. The apparatus of claim 8 , further comprising determining, by a configuration manager associated with the device, if the device is in the configuration lockdown mode.
11. The apparatus of claim 8 , wherein the one or more automated actions comprise one or more of generating a configuration lockdown alert and disabling the device.
12. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:
receiving a configuration command from a user to modify a configuration of at least a portion of a device;
in response to receiving the configuration command, performing the following steps:
determining whether the device is in a configuration lockdown mode that limits an execution of one or more configuration commands, wherein the received configuration command is distinct from a command to enable the configuration lockdown mode, wherein a duration of a disabling of the configuration lockdown mode is limited by one or more duration limits;
executing the received configuration command in response to determining that the device is not in the configuration lockdown mode and that the one or more duration limits are not violated; and
performing one or more automated actions and rejecting the received configuration command in response to determining that the device is in the configuration lockdown mode.
13. The non-transitory processor-readable storage medium of claim 12 , further comprising querying a configuration manager associated with the device to obtain the one or more duration limits for the configuration lockdown mode.
14. The non-transitory processor-readable storage medium of claim 12 , further comprising determining, by a configuration manager associated with the device, if the device is in the configuration lockdown mode.
15. The non-transitory processor-readable storage medium of claim 12 , further comprising evaluating one or more of credentials of the user and permissions of the user to execute the configuration command.
16. The method of claim 1 , wherein the configuration lockdown mode limits the execution of one or more configuration commands during the configuration lockdown mode to only one or more authorized users, wherein an authorization of a given user is based on a role of the given user within an organization, and wherein the one or more automated actions are performed in response to further determining that the received configuration command is from an unauthorized user.
17. The method of claim 1 , wherein the device is automatically placed in the configuration lockdown mode by default.
18. The apparatus of claim 9 , further comprising evaluating credentials of the user.
19. The apparatus of claim 8 , wherein the device is automatically placed in the configuration lockdown mode by default.
20. The non-transitory processor-readable storage medium of claim 13 , further comprising evaluating credentials of the user.