Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ruan_Kotze
Advisor

Change VPN client authentication option

Hi CheckMates,

We are transitioning our VPN to authentication via Entra, primarily to enforce MFA.

My question relates to migrating the client settings. Is there a way to accomplish this by manipulating the Authentication settings on the gateway? What I have done is made the MFA option the first priority in the Multiple Authentication Options list.

On the client side this results in the MFA option being labelled as the default, but it seems that regardless of that the client just uses the last succesful authentication method.

Is there anything we can do to flip the clients over to the MFA login option without needing to touch the client?

Thanks,
Ruan

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

You're using SAML, correct?
As I recall, this requires deleting and re-adding the site.

0 Kudos
Ruan_Kotze
Advisor

Yep using SAML and that part is working very well.

Automating re-creating the sites with update_config_tool seems to be going well when manually testing.  Need to wrap it inside a PS script then test it as part of push job in Harmony Endpoint today and see where that brings me.

Will share my learnings here if / when I get it going.

0 Kudos
the_rock
Legend
Legend

I see what Phoneboy is saying. I recall while ago thats what one of the customers I was helping had to do. Not sure if there is better method these days.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events