Ben Watts
Articles
-
How To: Confirm Groups Are Passed as a SAML Attribute
Version Affected: All OverviewDuring a new integration, it can be useful to verify that certain groups are being passed as part of a SAML attribute. Confirm Groups Are Passed in the SAML Assertion ...
-
How To: Change the Text Shown to End Users During RADIUS Authentication
Version Affected: RADIUS 2.x and later OverviewThis article explains how to change the wording shown to end users when they select a multi-factor authentication (MFA) method during RADIUS authentic...
-
Troubleshooting: FileSync Creates Lowercase Realm Folder and IIS App Names
Version Affected: FileSync 4.0.13 and lower OverviewOn the secondary server(s), realm folder and IIS application names created by FileSync are all lowercase, instead of matching the master server'...
-
How To: Copy an Existing New Experience Realm
Version Affected: 23.07 and later OverviewThis article explains how to create a New Experience realm by copying an existing New Experience realm, carrying over its configuration instead of building...
-
Troubleshooting: OIDC Password Grant Type Does Not Honor Group Restrictions
Version Affected: All OverviewWhen using the OIDCToken endpoint with the Password grant type, Group Restriction checks are not performed. CauseGroup Restriction and Adaptive Authentication setting...
-
Troubleshooting: L4W Stops Prompting for MFA After Reboot When McAfee Drive Encryption Is Installed
Version Affected: SecureAuth IdP 9.2 and later; Login for Windows (L4W) 1.0.4 and later OverviewAfter installing Login for Windows (L4W), the user isn't prompted for multi-factor authentication (M...
-
Troubleshooting: Cannot Find an AD Attribute to Delegate Permissions for User Objects
Version Affected: All OverviewWhen trying to delegate permissions to a specific Active Directory (AD) attribute for User objects -- for example, registeredAddress -- the attribute doesn't appear i...
-
How To: Use CredSSP/NLA for SSO with RDWeb Apps
Version Affected: All OverviewThis article explains how to use CredSSP on domain-joined machines so users aren't prompted to re-enter their credentials when launching a Remote Desktop Web Access (R...
-
How To: Prevent Double Authentication With Palo Alto GlobalProtect and RADIUS
Version Affected: All OverviewThis article explains how to prevent GlobalProtect from prompting for authentication a second time when integrating Palo Alto GlobalProtect with RADIUS. Without this c...
-
Troubleshooting: mS-DS-ConsistencyGuid Attribute Returns Garbled Data in a SAML Assertion
Version Affected: All (see Resolution for the specific fixed-in versions) OverviewWhen a realm's Data tab maps the Active Directory (AD) mS-DS-ConsistencyGuid attribute -- for example, as the Sour...