Allowing two-factor authentication for Active Roles users
To allow Active Roles users to use two-factor authentication, add the users to the ARS 2FA Users group. Adding the users to the ARS 2FA Users group enables the minimal permissions on the users through the Starling - Two Factor Authentication User Access template to authorize the users for two-factor authentication.
In case of multiple managed domains, the ARS 2FA Users group must be created manually in each of the domains and the Starling - Two Factor Authentication User Access template must be applied on the group.
Steps to create ARS 2FA Users group manually
- Create the ARS 2FA Users group in the Builtin container.
- Apply the Starling - Two Factor Authentication User Access template to the Domain.
- Run the following command in the Active Roles Management Shell:
new-QARSAccessTemplateLink -AccessTemplate 'CN=All Objects - Read All Properties,CN=Active Directory,CN=Access Templates,CN=Configuration' -DirectoryObject 'CN=Starling Configuration,CN=Configuration' -Trustee 'Domain\ARS 2FA Users' -Proxy
- Add AD users to the group.
Registering to One Identity Starling 2FA
In order to use Starling 2FA, you must first register to the product. When you register to Starling 2FA using your mobile number, an SMS is delivered with the mobile app download link. Click on the link to access the App Store or Play Store from where you can download the Starling mobile application. Alternatively, you can go to the App Store or Play Store and search and download the Starling.
The following 2FA options are supported:
- Push Notification: After the Starling app is downloaded and registered with user’s email id and mobile number, the user will get a push notification to Approve or Deny Starling Authentication.
- Voice: The user will get a voice call on the registered mobile number and on call user will get an OTP.
- SMS OTP: The user will get an OTP through SMS on the registered mobile number.
- The user can open the Starling app and copy and paste the code form the Starling app to Active Roles, and then click on Verify.
Logging in to Web interface through 2FA authentication
When a Starling 2FA enabled user tries to log in to the Active Roles Web interface, the user is prompted to enter the Starling Two-factor token response. Based on the option selected by the user, the token response is provided through SMS, Phone Call or Push Notifications.
On entering the token response and after successful verification the Web interface is displayed.
|
NOTE: Push Notification works only if the Starling App is installed on the device with registered mobile number. The link to install the Starling App will be send to your registered mobile number at the time of registering to Starling. |