How To: Prompt for 2FA on a Specific Application Within SecurePortal

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    SecurePortal allows single sign-on (SSO) to every application within it by default. This article explains how to make a specific application inside SecurePortal prompt for two-factor authentication (2FA) again, instead of relying on the portal's existing SSO session.

     

    Cause

    In a typical SecurePortal setup, the Post-Auth cookie name and the Forms Authentication name are the same across every realm in the portal, including the SecurePortal realm itself, as shown below. This is what lets a user move between applications without authenticating again.

    Forms Authentication and Authentication Cookies sections showing the same Post-Auth Cookie name, PostAuthToken11, used for both the Forms Authentication Name and the Post-Auth Cookie.

    Resolution:

    For the specific realm you want to step up authentication for:

    1. Swap the realm's Pre-Auth and Post-Auth/Forms Authentication cookie names, as shown below — set the Forms Authentication Name to a new value, put that same new value in Post-Auth Cookie, and put the SecurePortal's original Post-Auth cookie name in Pre-Auth Cookie instead.

    Forms Authentication and Authentication Cookies sections with the cookie names swapped, so Pre-Auth Cookie now holds the SecurePortal's original Post-Auth Cookie value.

    1. On the realm's Workflow tab, under Custom Identity Consumer, set Receive Token to Token, and set Allow Transparent SSO to False, as shown below. This lets the realm reuse the username from the portal's session without requiring it to be re-entered, while still requiring 2FA.

    Custom Identity Consumer settings with Receive Token set to Token and Allow Transparent SSO set to False, and a Begin Site configured to require access via the portal realm.

    Optionally, also set Require Begin Site to True with a Begin Site URL pointing at the SecurePortal realm, as shown above, so users cannot reach this realm directly without going through SecurePortal first.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.