Forum Discussion
Radius Authentication with Microsoft NPS and Azure MFA not working
- Apr 16, 2021
which version are you on? I can see this feature from 13.x and onwards.
By default apm uses session.logon.last.username variable for username. See if you can set custom APM variable for it and change it to UPN variable you get after LDAP query.
Sanjay. Thanks for the reply. How do i get username source and password source attributes in my radius AAA in VPE. how to add the two attributes.
when you select radius auth action in access policy those variables are added by default. You can read more below
- Raghbir_SandhuApr 16, 2021Altocumulus
Sanjay, I don't see the additional two attributes. see the attached screenshot.
- spalandeApr 16, 2021Nacreous
which version are you on? I can see this feature from 13.x and onwards.
By default apm uses session.logon.last.username variable for username. See if you can set custom APM variable for it and change it to UPN variable you get after LDAP query.
- Raghbir_SandhuApr 16, 2021Altocumulus
we are using 12.1.5.3. May be that's why I don't see two additional variables. what the question remain same. The radius request attribute name is "User-Name". can i just assign UPN value to the "User-Name" attribute via variable assignment step. before the MFA step. Please advise.
- spalandeApr 19, 2021Nacreous
- LDAP query to get UPN
- Set custom variable for session.logon.last.username to UPN variable
- Radius auth
- spalandeApr 20, 2021Nacreous
Have you made this working? It would be good to share your solution, it may benefit others using similar setup. Thanks!
- Raghbir_SandhuApr 20, 2021Altocumulus
Yes. It is working. I ended up creating registry entry "LDAP_ALTERNATE_LOGINID_ATTRIBUTE". Some how our NPS not able to process the User-Name attribute properly passed from F5 Radius authentication request. That fixed our problem and I don't have to do the LDAP query for UPN attribute.
Thanks,
Raghbir Sandhu
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com