I have the following requirement:
- Client running Identity agent full with Packet tagging
- Authentication of user by Radius with MFA
- Acquiring Machine Identity
If I'm not mistaken machine authentication with Identity agent is only working with Kerberos.
But if Kerberos is active, also the user is authenticated using Kerberos und with that we are not using MFA to authenticate the user, as the Radius is skipped.
Any chance we get the machine identity using Kerberos and don't allow user logon with Kerberos to force Radius auth?