Forum Discussion

WUM_113639's avatar
WUM_113639
Icon for Nimbostratus rankNimbostratus
Nov 17, 2014

Send OTP SMS or Email based on AD Group selection

Hello Experts,

 

Currently, we are using OTP for all the AD Users. Even if they are not supposed to use SSL VPN, they can login successfully with AD and have OTP sent to them via Email & SMS.

 

My VPE Policy...

 

Login > AD Auth > AD Query > Variable Assign > OTP Macro

 

We have a management requirement for not generating OTP if a user is not part of a certain VPN Group. We have created new AD Groups for only VPN users...such as ... APM_EMAIL, APM_SMS, APM_EMAIL_SMS.

 

So, if a user is part of APM_EMAIL group, he should only get email for the OTP and if the user is part of SMS group, he should only get SMS, and likewise if the user is part of EMAIL_SMS group then he would get both.

 

I need help on how to meet the requirements!

 

1 Reply

  • In your AD query, create a branch rule for each group, with the expression "AD Query, User is a member of" and enter the DN for the group. You can then do your email/SMS actions off of each branch.