RSA Product/Service Type: Authentication Agent for AD FS
RSA Version/Condition: 1.x
Through the AD FS Management tool, one can set a global authentication policy that applies to all relying party apps, or a per a relying party trust policy that applies to a specific relying party app. The first screenshot below shows an example of a global policy configured to require all extranet users to use multi-factor authentication (MFA) when accessing any web app protected by AD FS.
Note the extranet and intranet checkboxes. Extranet means that the authentication request is coming through a Web Application Proxy (see https://technet.microsoft.com/en-us/library/hh831502.aspx).
MFA policy can also be applied to specific users and groups as well as to registered and unregistered devices. (Device registration is Microsoft’s lightweight domain registration support where a device like an iPhone can be registered and used as an authentication factor.) When requiring a user or group to use MFA, it is Active Directory users and groups that are used. (AD FS can be thought of as an IDP for Active Directory.)
The second screenshot shows an example of an MFA policy defined for a specific relying party app, Outlook Web App (OWA). The policy requires that external users of OWA perform a SecurID authentication. Internal users of OWA are not required to perform a SecurID authentication. OWA is an example of an Office 365 web app.
Related Articles
How to Synchronize Nested AD Group Users from an RSA SecurID Access Identity Source 141Number of Views RSA PAM Authentication Agent cannot challenge users in Active Directory groups 264Number of Views RSA announces the release of the RSA SecurID Software Token and SDK 2.3 for iOS 2Number of Views RSA Authentication Agent for Microsoft Windows: Domain users are not challenged when "Domain Users" group is nested in loc… 41Number of Views Why use RSA SecurID Access AD FS SAML integration rather than the RSA Authentication Agent for Microsoft AD FS 95Number of Views
Trending Articles
Troubleshooting RSA SecurID Access Identity Router to RSA Authentication Manager test connection failures RSA SecurID Software Token 5.0.2 Downloads for Microsoft Windows RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Governance & Lifecycle 8.0.0 Administrators Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory