How To: Set Up Hybrid New Experience Realms for External MFA and Internal WindowsSSO / IWA

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: 24.4.x

     

    Overview

    This article explains how to set up WindowsSSO / Integrated Windows Authentication (IWA) for internal access and multi-factor authentication (MFA) for external access, using two New Experience realms. Users go to Realm A first; based on their IP address, they are either prompted for MFA or redirected to Realm B for WindowsSSO / IWA.

     

    In this article

     

    Configuring Realm A (External Access)

    Realm A is the entry point for all users. It prompts for MFA by default, and redirects trusted internal IP addresses to Realm B instead.

    1. Create a new policy on Realm A for external access (MFA).
    2. On the Authentication Rules tab, add a new IP Range rule that redirects the user to Realm B for the WindowsSSO / IWA workflow if they are coming from a trusted internal IP range. Add an Else rule below it to prompt for MFA for all other logins.
    3. On the Login Workflow tab, select the desired login MFA workflow.

    Realm A Authentication Rules tab showing Rule 1: redirect to the Realm B URL if the user is coming from 2 specified IP addresses, with an Else rule below it set to Prompt for MFA for all other logins.

    Realm A Login Workflow tab showing the login experience set to Username and Password, MFA Method, with Enable QR Login turned off.

     


     

    Configuring Realm B (Internal WindowsSSO / IWA)

    Realm B is only reached by users on a trusted internal IP range redirected from Realm A, and handles WindowsSSO / IWA for them without prompting for MFA again.

    1. Create a new policy on Realm B for internal access (WindowsSSO / IWA).
    2. On the Authentication Rules tab, add a new IP Range rule to skip MFA if the user is coming from a trusted internal IP range. Add an Else rule below it to prompt for MFA for all other logins.
    3. On the Login Workflow tab, select Passwordless.
    4. Go to Advanced Settings and select the Realm B workflow tab.
    5. Scroll down to the Custom Identity Consumer section and set the following:
      1. Receive Token: Token
      2. Require Begin Site: True
      3. Begin Site: Windows SSO
      4. Begin Site URL: WindowsSSO.aspx
      5. User Impersonation: True
      6. Windows Authentication: True

    Realm B Authentication Rules tab showing Rule 1: Skip MFA if the user is coming from 2 specified IP addresses, with an Else rule below it set to Prompt for MFA for all other logins.

    Realm B Advanced Settings Custom Identity Consumer section showing Receive Token set to Token, Require Begin Site set to True, Begin Site set to Windows SSO, Begin Site URL set to WindowsSSO.aspx, User Impersonation set to True, and Windows Authentication set to True.



     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.