Version Affected: 24.4.x
Overview
This article explains how to set up WindowsSSO / Integrated Windows Authentication (IWA) for internal access and multi-factor authentication (MFA) for external access, using two New Experience realms. Users go to Realm A first; based on their IP address, they are either prompted for MFA or redirected to Realm B for WindowsSSO / IWA.
In this article
Configuring Realm A (External Access)
Realm A is the entry point for all users. It prompts for MFA by default, and redirects trusted internal IP addresses to Realm B instead.
- Create a new policy on Realm A for external access (MFA).
- On the Authentication Rules tab, add a new IP Range rule that redirects the user to Realm B for the WindowsSSO / IWA workflow if they are coming from a trusted internal IP range. Add an Else rule below it to prompt for MFA for all other logins.
- On the Login Workflow tab, select the desired login MFA workflow.
Configuring Realm B (Internal WindowsSSO / IWA)
Realm B is only reached by users on a trusted internal IP range redirected from Realm A, and handles WindowsSSO / IWA for them without prompting for MFA again.
- Create a new policy on Realm B for internal access (WindowsSSO / IWA).
- On the Authentication Rules tab, add a new IP Range rule to skip MFA if the user is coming from a trusted internal IP range. Add an Else rule below it to prompt for MFA for all other logins.
- On the Login Workflow tab, select Passwordless.
- Go to Advanced Settings and select the Realm B workflow tab.
- Scroll down to the Custom Identity Consumer section and set the following:
- Receive Token: Token
- Require Begin Site: True
- Begin Site: Windows SSO
- Begin Site URL: WindowsSSO.aspx
- User Impersonation: True
- Windows Authentication: True
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.