One Identity Defender can be used for multi-factor authentication on One Identity Manager tools and the Web Portal . A Redistributable STS (RSTS) is set up to provide Active Directory authentication over a RADIUS server.
Prerequisite
- One Identity Defender is installed and set up.
To set up multi-factor authentication using Defender
-
Install the RSTS.
In the Installation Wizard on the Installation Settings page, enter the signing certificate, URL, and configuration password for the RSTS administration interface. For test or demonstration environments, you can use the Redistributable STS Demo signing certificate.
-
Configure the RSTS.
-
Set up the OAuth 2.0/OpenID Connect configuration.
In doing so, you create a new identity provider. You will need this identity provider for configuring authentication with Oauth 2.0/Openid Connect.
-
Configure authentication with Oauth 2.0/Openid Connect for the Web Portal.
-
Configure authentication with OAuth 2.0/OpenID Connect for the One Identity Manager administration tools.
-
Test the access to the Web Portal.
-
After entering the URL of the Web Portals in your web browser, you should be redirected to the RSTS login page.
-
After logging in with user name and password, you are prompted to enter your Defender Token.
If both authentications were successful, you can work with the Web Portal.
-
-
Test access to the One Identity Manager administration tools.
-
Start an administration tool, for example, the Launchpad, and select the OAuth 2.0/OpenID Connect authentication method.
-
After logging in with user name and password, you are prompted to enter your Defender Token.
If both authentications were successful, you can work with the administration tool.
-