Pricing  Get Quote
 
 

Common VPN and RADIUS-based endpoints and the ADSelfService Plus authenticators they support

ADSelfService Plus supports the following types of authenticators for VPN MFA:

  1. One-way authenticators
    • Push Notification Authentication
    • Fingerprint/Face ID Authentication

    These authenticators are automatically applicable for all the endpoints providing RADIUS authentication.

  2. Challenge-based authenticators
    • ADSelfService Plus TOTP Authentication
    • Google Authenticator
    • Microsoft Authenticator
    • Yubico OTP (hardware key authentication)
    • SMS verification and email verification
    • Zoho OneAuth TOTP

    Challenge-based authenticators are applicable only when:

    • PAP is configured for RADIUS authentication.
    • The RADIUS client (VPN or endpoint server) supports challenge-response; that is, it prompts a challenge (verification code) from the user and sends back the entered challenge.

While ADSelfService Plus provides MFA enablement for all RADIUS-based VPN providers, not all authenticators supported by the product are available in these providers. This article provides a list of popular VPN providers and other RADIUS-based clients and the authenticators supported by them.

VPN and other RADIUS clients Supports one-way authenticators provided in ADSelfService Plus? Supports challenge-based authenticators provided in ADSelfService Plus?
Fortinet VPN Yes Yes
OpenVPN Access Server (AS) Yes Yes
Cisco ASA AnyConnect VPN Yes Yes
NetMotion Mobility VPN Yes No
Microsoft RDGateway Yes No
Microsoft Routing and Remote Access Service (RRAS) Yes No
Palo Alto VPN (GlobalProtect client) Yes Yes
WatchGuard VPN Yes No
Sonic Wall VPN Yes Yes
Pulse Secure VPN Yes Yes
Juniper Yes Yes
Checkpoint Yes Yes
VMWare Horizon Yes Yes
ForcePoint Yes Yes
Cisco Meraki Yes No
Citrix/NetScaler Gateway Yes No

Note: Status of authenticator availability may change in the future.

Disclaimer : While the VPN providers listed above have been officially tested and confirmed to support the authenticators mentioned, other VPN providers and endpoints employing RADIUS protocol for authentication can support these authenticators as well. Please contact the support team ( support@adselfserviceplus.com ) if you have trouble assessing whether the VPN provider used in your organization supports these authenticators.

Request for Support

Need further assistance? Fill this form, and we'll contact you rightaway.

  • Name
  •  
  • Business Email *
  •  
  • Phone *
  •  
  • Problem Description *
  •  
  • Country
  •  
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.
Highlights of ADSelfService Plus

Password self-service

Allow Active Directory users to self-service their password resets and account unlock tasks, freeing them from lengthy help desk calls.

One identity with single sign-on

Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications using their Active Directory credentials.

Password and account expiry notification

Intimate Active Directory users of their impending password and account expiry via email and SMS notifications.

Password synchronization

Synchronize Windows Active Directory user passwords and account changes across multiple systems automatically, including Microsoft 365, Google Workspace, IBM iSeries, and more.

Password policy enforcer

Strong passwords resist various hacking threats. Enforce Active Directory users to adhere to compliant passwords by displaying password complexity requirements.

Directory self-update and corporate directory search

Enable Active Directory users to update their latest information themselves. Quick search features help admins scout for information using search keys like contact numbers.

ADSelfService Plus trusted by

Embark on a journey towards identity security and Zero Trust