Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AkiYa
Contributor

Multiple login methods - disable user+pass method for some users only

Hi guys,

I have my firewall configured with three RAS methods, two using multi-factor authentication (radius and SAML) and the old "Username_Password" method which I need to dismiss asap.

Since I can't just remove the legacy method for everyone, I' m wondering if it would be possible to block this way to connect for only some users, let's say the users in a specific AD group.

I made some tries but since my test user is in the group allowed to connect with MFA, it seems that if I select the legacy method from the Endpoint Connect client it will be accepted anyway and it can connect.

Is this possible or I have to completely remove the method from the firewall?

Thanks

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

If the user can successfully authenticate with the chosen method, they will be allowed to use it.
I suspect you'll have to remove the method entirely.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events