Skip to content

GitLab identity, MFA & sign-in security checks

Who can sign in, how strongly they authenticate, and whether sessions, passwords and sign-in locations meet the baseline every admin account should clear.

On GitLab, Black Cat runs 4 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the GitLab connector needs.

Checks (4)

severity: critical Group 2FA Not Enforced fix difficulty: easy #

Enforce two-factor authentication for all members of the GitLab group

  1. Navigate to GitLab Group Settings > General > Permissions and group features
  2. Enable 'Require all users in this group to set up two-factor authentication'
  3. Set an appropriate grace period for existing members

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: medium Group 2FA Grace Period Too Long fix difficulty: easy #

Reduce the GitLab group 2FA grace period to 48 hours or less

  1. Navigate to Group > Settings > General > Permissions
  2. Reduce 2FA grace period to 48 hours or less
  3. Save changes
  4. Notify members about the shorter enforcement window

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: high Member Without 2FA fix difficulty: easy #

Contact GitLab group members who have not enrolled in 2FA and direct them to set it up

  1. Contact the group member to enable 2FA on their GitLab account
  2. Direct them to GitLab User Settings > Account > Two-Factor Authentication
  3. Verify enrollment after the grace period

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.5 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.3 NIST CSF 2.0 PR.AA-03 GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

severity: critical Group Owner Without 2FA fix difficulty: easy #

Ensure all group owners have two-factor authentication enabled immediately

  1. Contact the group owner to enable 2FA on their GitLab account
  2. Direct them to User Settings > Account > Two-Factor Authentication
  3. Verify enrollment within 24 hours
  4. Consider temporarily reducing their access level until 2FA is enabled

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.j DORA (SaaS Security) DORA-9.4

More GitLab checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial