RADIUS-Complaint Authentication

RADIUS server or any RADIUS-Compliant two-factor authentication system (like Vasco Digipass) can be integrated with Access Manager Plus for two factor authentication. Remote Authentication Dial-In User Service (RADIUS) is a protocol that allows remote access servers to communicate with central server to authenticate and authorize access to the requested system.

Prerequisites

  1. Provide basic details about RADIUS server.
  2. Enable the RADIUS-based authentication system as the second factor.

Summary of Steps

  1. Configuring Two-Factor Authentication in Access Manager Plus
  2. Enforcing Two-Factor Authentication for Required Users
  3. Connecting to Access Manager Plus Web Interface when TFA through RADIUS Authenticator is Enabled

1. Configuring Two-Factor Authentication in Access Manager Plus

  1. Navigate to Admin >> Authentication >> Two-factor Authentication.
  2. Choose the option RADIUS Authenticator.
  3. Provide the following details in the drop down form:
  • Click Save.

  • Click Confirm to enforce Radius Authenticaor as the second factor of authentication.

  • 2. Enforcing Two-Factor Authentication for Required Users

    1. Once Radius Authenticator is confirmed as the second factor of authentication, a new window will prompt you to select the users for whom Two-Factor Authentication should be enforced.
    2. You can enable or disable two-factor authentication for a single user or multiple users in bulk from here. To enable Two-Factor Authentication for a single user, click on the Enable button beside their respective usernames. For multiple users, select the required usernames and click on Enable at the top of the user list. Similarly, you can also Disable two-factor authentication from here.

    3. You can also select the users later by navigating to Users >> More Actions >> Two-Factor Authentication.

    3. Connecting to Access Manager Plus Web Interface when TFA through RADIUS Authenticator is Enabled

    The users for whom Two-Factor Authentication is enabled, will have to authenticate twice successively. As explained above, the first level of authentication will be through the usual authentication. That is, the users have to authenticate through Access Manager Plus's local authentication or AD/LDAP authentication. If the administrator has chosen the TFA option RADIUS Authenticator, the Two-Factor Authentication will happen as detailed below:

    1. Upon launching the Access Manager Plus web-interface, the user has to enter the username and local authentication or AD/LDAP password to login to Access Manager Plus and click Login.
    2. Once the first level of authentication succeeds, you will be prompted to enter the RADIUS code.

    See also:

    Top