How To: Configure RADIUS to Accept Domain\Username Format Logins

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    By default, SecureAuth RADIUS does not recognize a Domain\Username login format. This article covers how to configure a realm and the RADIUS server so it does.

     

    Configure Domain\Username Support

    1. On the realm's Data tab, set Datastore Type to Active Directory (UPN).

    Membership Connection Settings with Datastore Type set to Active Directory (UPN).

    1. Configure the realm's API Key, then add the resulting Application ID and Application Key to the corresponding RADIUS server's IdP Realm settings.

    The realm's API Key section, with Enable API for this realm checked and Application ID and Application Key generated under API Credentials.

    The RADIUS server's Edit IdP Realm settings, with API Application ID and API Application Key fields populated (masked).

    1. On the RADIUS server, create the file C:\idpRADIUS\bin\conf\domainUPNSuffixes.properties if it doesn't already exist -- create it using a text editor running as Administrator. Add one entry per domain, converting each domain's short name to its UPN suffix, for example contoso=contoso.local, then save the file.

    When a user enters a Domain\Username value in the RADIUS login prompt, the RADIUS server automatically converts it to UPN format using this file, so the client integrated with RADIUS now accepts the Domain\Username format.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.