JTF-GNO COMMAND TASK ORDER (CTO) 06-02, update 3 requires two-factor authentication for all DOD private web servers. The Visual Studio Team Foundation Server application tier runs on Internet Information Server that is considered a DOD private web server. Since the Visual Studio Team Foundation Server Client was not designed to pass a client certificate to the application tier, this product is in violation of this Department of Defense Information Assurance policy and as such will need to be removed from our development infrastructure if Microsoft doesn't create a hot fix for this issue. Microsoft's business will also be negatively impacted because VSTS, in its current form, cannot be leveraged within any DoD installation.
Jason Camp, MCSE, MCSD, MCDBA, MCAD, MCSA, CISSP, SCSA
Jason D. Camp
Thanks for raising this issue, we have only recently become aware of this issue and are digging into it to ensure we fully understand it and then determine our next steps.
Jim Boyle
Thanks for your reply. Hopefully I'll hear back from Microsoft on the status soon so that I can post their answer to this issue.
Jason Camp, MCSE, MCSD, MCDBA, MCAD, MCSA, CISSP, SCSA