This article describes how to integrate SFTPPlus MFT with RSA Authentication Manager (AM) using RADIUS.
Configure AM
Prerequisite
Before proceeding, ensure Active Directory is integrated with RSA Authentication Manager and that you have assigned a token to at least one Active Directory user.
Perform these steps to configure AM using RADIUS.
Procedure
- Sign in to the Security Console.
- Go to RADIUS > RADIUS Servers.
- Navigate to RADIUS > RADIUS Clients and click Add New.
- On the Add RADIUS Client page, enter the following:
- Client Name: Enter a descriptive name for the RADIUS client.
- IPv4 Address: Enter the IP address of the RADIUS client (SFTPPlus MFT).
- Make/Model: Standard Radius.
- Shared Secret: Create and enter a secure shared secret. This secret will be used for secure communication between the RADIUS client and the RADIUS server.
- Click Save & Create Associated RSA Agent.
- On the Add New Authentication Agent page, click Save, then confirm by clicking Yes, Save Agent.
Notes:
- Ensure that the IP address configured for the RADIUS client matches the exact source IP address used by the SFTPPlus MFT server when initiating outbound connections to AM.
- If the SFTPPlus MFT server uses multiple source IP addresses, you can configure additional IP addresses in the Alternate IP Addresses field of the corresponding SFTPPlus MFT RSA Agent configuration within AM.
Configure SFTPPlus MFT
Prerequisites
- This guide assumes that SFTPPlus MFT is already installed and operational in your environment.
- The integration procedures described in this guide are platform-independent and apply to SFTPPlus MFT deployments running on Windows, Linux, macOS, Docker, Kubernetes, and other supported platforms.
The integration described in this guide demonstrates how to authenticate Windows domain users using their username and password, and then perform RSA SecurID token validation as an additional authentication method.
Procedure
- In the SFTPPlus management interface, create a new RADIUS Authentication Method.
- Configure the authentication method to connect to the AM RADIUS server.
- Enable the authentication method and configure it to be used as second-factor authentication.
Configure Windows Domain Authentication
Configure SFTPPlus to perform first-factor authentication against the Windows Domain users together with second-factor authentication via AM.
- Create a new Operating System Authentication Method in SFTPPlus.
- Configure the authentication method to authenticate users against the Windows domain.
- Restrict access to specific Windows groups by configuring the appropriate group membership settings. This ensures that only authorized domain users can access SFTPPlus file transfer services.
- Verify that second-factor authentication remains enabled for this authentication method.
Validate the Integration
- Sign in to SFTPPlus using an SFTP client.
- When prompted, enter your Windows domain username and password.
- After the primary credentials are successfully validated, enter your RSA SecurID token when prompted.
Successful validation of both factors confirms that SFTPPlus is authenticating users through the Windows domain and AM.
The following is an example of an SFTP session authentication interaction.
$ sftp -P 10022 win-ad-user@sftpplus.acme.com
Welcome to ACME Inc SFTP Service
RSA SecurID MFA required
(win-ad-user@sftpplus.acme.com) Domain password>
More credentials required
First factor accepted. Second factor required.
(win-ad-user@sftpplus.acme.com) RSA AuthMan v8.7.1:
Note: SFTPPlus supports the creation of multiple user groups, allowing you to assign different levels of file transfer access and permissions based on group membership.
The configuration is complete.
Related Articles
SFTPPlus MFT - RSA Ready Implementation Guide 1Number of Views FortiGate Firewall - RADIUS Configuration Using SSL VPN - RSA Ready Implementation Guide 106Number of Views Citrix NetScaler - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide 1Number of Views Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 718Number of Views CyberArk Password Vault Web Access - RADIUS Configuration with Authentication Manager - RSA Ready Implementation Guide 159Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide