If MFA for VPN and RADIUS endpoints is not working, refer to the following troubleshooting points. By default, the NPS extension logs can be found at C:\Program Files\ManageEngine\Identity360 Cloud NPS Extension\logs. The logs are stored in idsagent-common.log file.
There are multiple possible causes for this issue. Use the steps below to identify and resolve them.
Cause 1: Connectivity issue between Identity360 and the NPS server.
How to check: Look for the error code IDS-4106 in the logs at: C:\Program Files\ManageEngine\Identity360 Cloud NPS Extension\logs\idsagent-common.log.
Solution:
Cause 2: MFA is not enabled in Identity360.
How to check: In the admin portal, go to Applications > Multi-factor Authentication > MFA for Endpoints > VPN and RADIUS Endpoints and verify if additional authentication factors are enabled.
Solution: Complete the MFA configuration for VPN and RADIUS Endpoints by following the steps here.
Cause 3: User is invalid or not licensed for MFA.
How to check:
Solution:
Cause 4: User is not fully enrolled for the required MFA factors.
How to check: In the admin portal, go to Reports > Universal Directory > MFA Reports > Enrolled Users and check if the user is enrolled for the MFA factors configured in Applications > Multi-factor Authentication > MFA for Endpoints > VPN and RADIUS Endpoints.
Solution:
Cause 5: NPS extension is unable to read OTP or TOTP from the RADIUS request.
How to check:
Solution:
Cause 6: Request is bypassed due to NPS extension filtering based on custom settings.
How to check: Look for the error code IDS-4104 in the logs at: C:\Program Files\ManageEngine\Identity360 Cloud NPS Extension\logs\idsagent-common.log.
Solution:
There are multiple possible causes for this issue. Use the steps below to identify and resolve them.
Cause 1: Connectivity issue between Identity360 and the NPS server.
How to check: Look for the error code IDS-4106 in the logs at: C:\Program Files\ManageEngine\Identity360 Cloud NPS Extension\logs\idsagent-common.log.
Solution:
Cause 2: User is not fully enrolled for the required MFA factors.
How to check: Go to Reports > Universal Directory > MFA Reports > MFA Attempts and check if the status shows a not enrolled error.
Solution:
Cause 3: Incorrect passwordless authentication configuration.
How to check: If the NPS extension was installed before enabling passwordless authentication in Identity360, the configuration may be incomplete, leading to VPN access issues.
Solution: Reinstall the NPS extension after enabling passwordless authentication in Identity360 under Applications > Multi-factor Authentication > MFA for Endpoints > VPN and RADIUS Endpoints to ensure proper configuration.
Cause 4: Access is denied when passwordless Authentication is enabled.
How to check:
Solution: Follow the corresponding solutions to resolve the issue.
Cause: When using VPN Client Verification, the RADIUS attributes configured in the network policy of the NPS server are not sent to the RADIUS client, such as a VPN or endpoint server. This can result in incorrect access levels, giving the user too much access, too little access, or no access at all.
Solution: Instead of relying on the NPS server to send RADIUS attributes, enable the Send additional RADIUS attributes to the VPN server after successful authentication option under Advanced Settings to ensure that the correct RADIUS attributes are sent to the VPN server after MFA, allowing the right access permissions to be applied.
Cause: The RADIUS client, such as a VPN or endpoint server is stopping the MFA process due to minimal RADIUS timeout settings.
Solution: Check the RADIUS authentication timeout settings on both the RADIUS client (VPN server or other RADIUS clients) and the RADIUS server (NPS). The timeout should be longer than the MFA session time set for VPN in Identity360. For detailed steps, refer to the Advanced Settings document.
Error code | Description | Resolution |
---|---|---|
IDS-4101 | The server where the NPS Extension is installed cannot connect to the Identity360 portal. This code is logged when NPS Extension authorization fails due to an invalid or old installation key being used after generating a new one. | Get the valid or updated installation key from the Identity360 portal at Applications > Multi-factor Authentication > Install NPS Extension > Step 2, and attempt to reinstall the agent. |
IDS-4102 | The server where the NPS extension is installed cannot connect to the Identity360 portal. This code is logged when MFA is bypassed due to an unexpected failure in API authorization with Identity360. | Please attempt to reinstall the NPS extension. If the problem persists, please contact the support team at identity360-support@manageengine.com. |
IDS-4104 | This code occurs when the pre-validation conditions are not satisfied. |
|
IDS-4105 | The server where the NPS extension is installed cannot connect to the Identity360 portal. This code appears when the access token expires and authentication is bypassed. | Please reach out to the support team at identity360-support@manageengine.com, providing the NPS extension's logs located at C:\Program Files\ManageEngine\Identity360 Cloud NPS Extension\logs |
IDS-4106 | The server where the NPS extension is installed cannot connect to the Identity360 portal. In such cases, user access would either be denied, or MFA would be bypassed depending on whether BypassConnectionError key is set to true or false in the customizations.json file found at C:\Program Files\ManageEngine\Identity360 Cloud NPS Extension\conf. | Ensure the internet connection between the NPS server and Identity360 is stable, then try again. |
IDS-4107 | The server where the NPS extension is installed cannot connect to the Identity360 portal. This code is logged when an attempt to establish a secure HTTPS connection with the Identity360 portal fails due to an SSL certificate issue.
Or This error code is triggered during NPS extension installation if the device setup information is incorrect. |
Please reach out to the support team at identity360-support@manageengine.com.
Or Please ensure that you install the agent on machines that run only the operating systems supported by the NPS extension as per the system requirements. |
Copyright © 2024, ZOHO Corp. All Rights Reserved.