# APM Access Policy|SSLVPN | SAML auth questionnaires

**URL:** <https://community.f5.com/t/apm-access-policy-sslvpn-saml-auth-questionnaires/76089>\
**Category:** Technical Forums\
**Tags:** access-policy, 2fa, apm\
**Created:** [May 10, 2025, 9:50pm UTC](https://community.f5.com/t/apm-access-policy-sslvpn-saml-auth-questionnaires/76089 "2025-05-10T21:50:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![M\_Saeed](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@M\_Saeed](https://community.f5.com/u/M_Saeed)\
**Post date:** [May 10, 2025, 9:50pm UTC](https://community.f5.com/t/apm-access-policy-sslvpn-saml-auth-questionnaires/76089/1 "2025-05-10T21:50:56Z")

</div>

Hello All,

I had a conversation wiht tech team, they asking about APM login auth via SAML.  
We are deploying SSLVPN and we have specific EPS checks and MFA.

I have confirmed that in such approach we can’t auth login via SAML, as it is at the end a web based auth for a web services. Our deployment is based on edge client and we have a security posture to append.

I’m totally aware of such point, however&nbsp; we are in brainstorm mode here for such discussion  
any expert had any update or idea here ?

It was long time no see, and I’m glad to return back delivering for the community.

Thank you.

---

<div class="post-metadata">

**Author:** ![Injeyan\_Kostas](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/injeyan_kostas/32/263_2.png) [@Injeyan\_Kostas](https://community.f5.com/u/Injeyan_Kostas)\
**Post date:** [May 12, 2025, 4:06pm UTC](https://community.f5.com/t/apm-access-policy-sslvpn-saml-auth-questionnaires/76089/2 "2025-05-12T16:06:41Z")

</div>

Edge Client can use an embedded browser to perform SAML and MFA. Of course any EPS checks too

In the latest client though you can also use default system browser which is far better than Edge Client’s embedded browser.

Have you tried this?

---

<div class="post-metadata">

**Author:** ![M\_Saeed](https://avatars.discourse-cdn.com/v4/letter/m/dec6dc/32.png) [@M\_Saeed](https://community.f5.com/u/M_Saeed)\
**Post date:** [May 13, 2025, 6:37pm UTC](https://community.f5.com/t/apm-access-policy-sslvpn-saml-auth-questionnaires/76089/3 "2025-05-13T18:37:54Z")

</div>

Hello Injeyan,  
Thanks for your highlights. That what came to mind too.

Yet to proceed and verify it. However If I’m proceeding with SAML assertion I think no need for 2FA as after such assertion I would deliver assigned SSLVPN resources.

---

<div class="post-metadata">

**Author:** ![LiefZimmerman](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/liefzimmerman/32/3355_2.png) [@LiefZimmerman](https://community.f5.com/u/LiefZimmerman)\
**Post date:** [May 16, 2025, 9:27pm UTC](https://community.f5.com/t/apm-access-policy-sslvpn-saml-auth-questionnaires/76089/4 "2025-05-16T21:27:25Z")

</div>

Happy to have you back as well @M_Saeed &nbsp;  
Cheers
