Forum Discussion
2FA authentication with SSO on APM
Hi
i have configured two factor authentication with AD and RSA for users to connect to application on APM. but i need SSO configuration on APM to pass the AD credentials to application. the policy i have configured will change session.logon.last.password to password1 to pass the RSA token to RSA server.So how do i get actual AD password session ID to configure SSO.
Policy Logon page -- configured password1 as session variable for RSA--AD auth -- varible assign as below--RSA auth--SSO mapping - backend server Variable assign expr {[mcget session.logon.last.password1]}
- Lee_Sutcliffe
Nacreous
You need to create a SSO Credential Mapping policy agent in the Visual Policy Editor, that takes the username and password from the logon page, and maps them to variables to be used for SSO services
- Siphe
Nimbostratus
Hi Lee, tried this but unfortunately it doesn't resolve the issue.
- PSilvaRet. Employee
Post of the Week Video of the question:
https://devcentral.f5.com/articles/post-of-the-week-two-factor-auth-and-sso-with-big-ip-29546
ps
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com