Version Affected: Identity Platform 9.2 and later
Overview
After installing Login for Windows, regular users see the error "No two-factor authentication methods found" when logging in, even though a test user and users in the bypass group can log in without issue.
Cause
The affected users' machines do not trust the Identity Platform (IdP) server's certificate. You can confirm this by adding an affected user to the bypass group, logging in, then opening the SecureAuth server address in Internet Explorer — if a certificate warning appears, this confirms the certificate trust issue.
To resolve this:
- Log in to the machine as an Administrator.
- Open Internet Explorer and navigate to the SecureAuth site.
- Click the padlock icon to view the certificate.
- Click Certification Path.
- Select the Root Certificate and click View Certificate.
- Click Install Certificate and choose the store location Local Machine, so every user on this machine trusts the certificate.
- If the Install Certificate option is not available, the certificate has likely already been imported into the current user's own certificate store rather than the machine's. In this case, open the Microsoft Management Console (MMC) and use Add/Remove Snap-in.
- Add the Certificates snap-in for both Current User and Local Computer.
- Copy the SecureAuth G3 Root Certificate Authority from Current User | Trusted Root Certification Authorities to Local Computer | Trusted Root Certification Authorities, as shown below.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.