We have seen a large increase in the use of multifactor authentication for VPN access (endpoint, not portal). However, clients are saying that they don't need MFA for all users, only for certain groups of users (VIPs, admins, etc). They're part of the same AD, but some should be required to login with MFA, others only user/pw or only certificates.
We haven't found a way to do that with Multiple Login Options. We need to use the same Account Unit (multiple Units to the same domain cause conflicts), we cannot use a different VS for different group (overkill and not feasible).
We needan option in the User Directories of the Multiple Login Options, to be a specific LDAP group, or a specific usergroup within an LDAP Account Unit.
Anyone can think of another way to do this?
Remote Access VPN Identity Awareness