Chat now with support
Chat with Support

Identity Manager 9.1.2 - Authorization and Authentication Guide

About this guide One Identity Manager application roles Granting One Identity Manager schema permissions through permissions groups Managing permissions to program functions One Identity Manager authentication modules OAuth 2.0/OpenID Connect authentication Multi-factor authentication in One Identity Manager Granular permissions for the SQL Server and database Installing One Identity Redistributable STS Preventing blind SQL injection Program functions for starting the One Identity Manager tools Minimum access levels of One Identity Manager tools

Multi-factor authentication with One Identity Defender

One Identity Defender can be used for multi-factor authentication on One Identity Manager tools and the Web Portal . A Redistributable STS (RSTS) is set up to provide Active Directory authentication over a RADIUS server.

Prerequisite
  • One Identity Defender is installed and set up.

To set up multi-factor authentication using Defender

  1. Install the RSTS.

    In the Installation Wizard on the Installation Settings page, enter the signing certificate, URL, and configuration password for the RSTS administration interface. For test or demonstration environments, you can use the Redistributable STS Demo signing certificate.

  2. Configure the RSTS.

  3. Set up the OAuth 2.0/OpenID Connect configuration.

    In doing so, you create a new identity provider. You will need this identity provider for configuring authentication with Oauth 2.0/Openid Connect.

  4. Configure authentication with Oauth 2.0/Openid Connect for the Web Portal.

  5. Configure authentication with OAuth 2.0/OpenID Connect for the One Identity Manager administration tools.

  6. Test the access to the Web Portal.

    • After entering the URL of the Web Portals in your web browser, you should be redirected to the RSTS login page.

    • After logging in with user name and password, you are prompted to enter your Defender Token.

    If both authentications were successful, you can work with the Web Portal.

  7. Test access to the One Identity Manager administration tools.

    • Start an administration tool, for example, the Launchpad, and select the OAuth 2.0/OpenID Connect authentication method.

    • After logging in with user name and password, you are prompted to enter your Defender Token.

    If both authentications were successful, you can work with the administration tool.

Detailed information about this topic

Configuring RSTS for multi-factor authentication

To configure multi-factor authentication using a RADIUS server on the RSTS

  1. Start a web browser and open the URL of the RSTS administration interface.

    https://<webapplication>/RSTS/admin

    Use the configuration password assigned during installation to log in.

  2. On the home page, click Authentication providers.

  3. On the Authentication Providers page, select the Default Active Directory default provider and click Edit.

  4. On the Edit page, select the Authentication provider tab and edit the following settings.

    • Directory Type > Active Directory: enabled

    • Connection Information > Use Current Domain: enabled

  5. Select the Two Factor Authentication tab and edit the settings for your Defender Security Server.

    • Two Factor Authentication Settings > RADIUS: enabled

    • Server, Port, Shared Secret and Username Attributes: Connection data for the RADIUS server.

    • (Optional) Connection Information > Pre-authenticate For ChallengeResponse: Uses the response text of the defender, instead of the default RADIUS response text.

  6. Switch to the home page and select Applications.

  7. On the Applications page, click Add Application.

  8. On the Edit page, select the General Settings tab and edit the following settings.

    • Application Name, Authentication Provider, Realm/Client_ID/Issuer, Redirect Url

    The redirect URL for the Web Portal (Redirect Url) is formed as follows: https://<Server>/<Application Name>/

  9. Select the Certificates tab and under Signing Certificate (Required) activate the signing certificate that you specified when installing the RSTS.

    For more information, see Multi-factor authentication with One Identity Defender.

  10. Click Finish.

Related topics

Configuring authentication with OAuth 2.0/OpenID Connect in the Web Portal

To configure authentication with OAuth 2.0/OpenID Connect

  1. Start the Web Designer.

  2. Click the View > Home page menu item.

  3. On the home page, click Select web application and select the web application.

  4. Click Edit web application settings.

  5. In the Edit web application settings dialog, edit the web application settings.

    • Authentication module: Select OAuth 2.0/OpenID Connect (role-based).

    • OAuth 2.0/OpenID Connect configuration: Select the newly created identity provider.

    • Client ID for OAuth 2.0 authentication: Select the client ID that you specified when you configured RSTS.

    • Fingerprint of the OAuth 2.0 certificate: Specify the fingerprint of the signing certificate you selected when configuring the RSTS.

  6. Save the changes.
Related topics

Configuring authentication with OAuth 2.0/OpenID Connect

To configure authentication with OAuth 2.0/OpenID Connect

  1. In the Designer, select the Base data > Security settings > OAuth 2.0/OpenID Connect configuration category.

  2. In the list editor, select the newly created identity provider.

  3. Select the General tab and check the general configuration data of the identity provider.

    • Column to search: Select ADSAccount - ObjectGUID.

  4. Select the Applications tab and check the configuration of the OAuth 2.0/OpenID Connect application.

    • Default: enabled

    • Redirect URI: If you want to use multifactor authentication with the administration tools of the One Identity Manager, enter urn:InstalledApplication.

  5. Select the Database > Commit to database and click Save.

Related topics
Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating