Forum Discussion
Send OTP SMS or Email based on AD Group selection
Hello Experts,
Currently, we are using OTP for all the AD Users. Even if they are not supposed to use SSL VPN, they can login successfully with AD and have OTP sent to them via Email & SMS.
My VPE Policy...
Login > AD Auth > AD Query > Variable Assign > OTP Macro
We have a management requirement for not generating OTP if a user is not part of a certain VPN Group. We have created new AD Groups for only VPN users...such as ... APM_EMAIL, APM_SMS, APM_EMAIL_SMS.
So, if a user is part of APM_EMAIL group, he should only get email for the OTP and if the user is part of SMS group, he should only get SMS, and likewise if the user is part of EMAIL_SMS group then he would get both.
I need help on how to meet the requirements!
1 Reply
In your AD query, create a branch rule for each group, with the expression "AD Query, User is a member of" and enter the DN for the group. You can then do your email/SMS actions off of each branch.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com