Two Factor Auth with ADFS 2.0?
-
Hi Da,
We will be providing more information on 2FA support together with ADFS2.0 and O365 shortly. In the meantime there are a few scenarios that we will support (that you could try out in Beta).
If you want to secure all your external originating client requests with 2FA (using RSA), there are 2 options for you - as long as your are securing web apps (like OWA, SharePoint etc - rich client apps like Outlook and Lync are not supported with 2FA currently in this mode):
1. Deploy an AD FS 2.0 proxy in your DMZ and then customize the AD FS proxy login page (which is an ASPX page) to integrate with the RSA servers. We don't yet have sample code for this I'm afraid, but we'll likely have something on this in the future.
2. Deploy ForeFront UAG SP1 in your DMZ. This proxy will publish the AD FS endpoints, and in additional to all the other great gateway features UAG has, it also boasts out of the box integration with RSA (plus libraries for integrating with other 2FA technologies). See:
· Overview of AD FS 2.0 with Forefront UAG
· Remote partner employee access using claims (this is similar to the Office 365 scenarios)
· Deploying Forefront UAG with AD FS 2.0
· Planning for front-end authentication (how to enable two-factor authentication)
Hope this helps. Please let me know if there are other scenarios that you are interested in for 2FA. I'd love to hear if you have any 2FA requirements around rich client and/or smart phones,
Dan.
-
Thanks for the info Dan, I'll engage the policy makers and let them do their thing.
I know all clients access requests originating from the internet are in scope for 2-Factor auth, which would include fat clients like Outlook rpc over https and Lync.
Intranet-originating requests are normal internal adfs 2.0 pass-through auth.
I suspect will need to be getting up to speed on the new Forefront very shortly. Even if we can only secure internet-originating OWA requests with two-factor, that would still be better than nothing.
Thanks,
Da
'한땀한땀 > Microsoft' 카테고리의 다른 글
Microsoft to Acquire Skype (0) | 2011.05.11 |
---|---|
Microsoft 제품 주기 검색 (0) | 2011.04.27 |
Outlook Anywhere with RSA authentication (0) | 2011.04.25 |
[스크랩]신뢰할 수 있는 컴퓨팅(Trustworthy Computing, TwC) (0) | 2011.04.22 |
Trustworthy Computing (0) | 2011.04.22 |