How To: Share a Login Session Between an MFA Realm and an IWA Realm Using Transparent SSO

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to let internal users authenticate via Integrated Windows Authentication (IWA) / WindowsSSO while external users still go through multi-factor authentication (MFA), using Transparent SSO (TSSO) to share the resulting login session across realms — without requiring users to sign in again on each realm they visit.

    This is intended for On-Premises or Hybrid deployments that do not have separate DMZ and Internal IdP appliances, and therefore cannot simply route internal and external users to two entirely separate appliances.

     

    Configuring Transparent SSO

    1. Pick a realm to act as the "main" entry point for internal users — this can be a portal realm or simply the realm your users already access most often.
    2. Set this realm up as usual for MFA, and create a duplicate realm configured for IWA / WindowsSSO. Use an Authentication Rule to move internal users from the main MFA realm to its IWA / WindowsSSO duplicate.
    3. On the IWA / WindowsSSO realm, edit the FormsAuth cookie settings so that the Forms cookie name and the Post Authentication cookie name match each other, and confirm the machine keys have been generated.
    4. Copy these same FormsAuth cookie and machine key settings to every other realm you want users to reach without re-entering credentials.
    5. On each participating realm, go to the Workflow tab and enable Transparent SSO.

     

    User Experience

    1. An internal user opens their browser, is routed to the IWA / WindowsSSO realm, and is signed in automatically. This creates the TSSO cookie.
    2. The user then goes to another realm that participates in the same TSSO group.
    3. Because the user already has a valid TSSO cookie, they are signed in automatically on that realm as well, without being prompted again.

     


     

    Special Considerations

    Transparent SSO is only as strong as your weakest participating realm, since every realm in the TSSO group is able to create the shared cookie after a successful login. Only apply Transparent SSO to realms that use the same workflow, policy, and adaptive authentication settings — a weaker realm in the group can otherwise let a user obtain a TSSO cookie without meeting the stronger requirements of the other realms.

    This article covers the FormsAuth cookie-sharing approach to combining internal IWA and external MFA access on Classic-style realm configurations. If you are configuring New Experience realms instead, see How To: Set Up Hybrid New Experience Realms for External MFA and Internal WindowsSSO / IWA, which uses IP-based Authentication Rules and the Custom Identity Consumer settings instead.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.