SFTPPlus MFT - RADIUS Configuration - Authentication Manager - RSA Ready Implementation Guide
Last Modified: 2026-10-01

This article describes how to integrate SFTPPlus MFT with RSA Authentication Manager (AM) using RADIUS.

    
Configure AM

Prerequisite

Before proceeding, ensure Active Directory is integrated with RSA Authentication Manager and that you have assigned a token to at least one Active Directory user.

Perform these steps to configure AM using RADIUS.

Procedure

  1. Sign in to the Security Console.
  2. Go to RADIUS > RADIUS Servers. 
  3. Navigate to RADIUS > RADIUS Clients and click Add New.
  4. On the Add RADIUS Client page, enter the following:
    1. Client Name: Enter a descriptive name for the RADIUS client.
    2. IPv4 Address: Enter the IP address of the RADIUS client (SFTPPlus MFT).
    3. Make/Model: Standard Radius.
    4. Shared Secret: Create and enter a secure shared secret. This secret will be used for secure communication between the RADIUS client and the RADIUS server.
  5. Click Save & Create Associated RSA Agent.
  6. On the Add New Authentication Agent page, click Save, then confirm by clicking Yes, Save Agent.

Notes:

  • Ensure that the IP address configured for the RADIUS client matches the exact source IP address used by the SFTPPlus MFT server when initiating outbound connections to AM.
  • If the SFTPPlus MFT server uses multiple source IP addresses, you can configure additional IP addresses in the Alternate IP Addresses field of the corresponding SFTPPlus MFT RSA Agent configuration within AM.

  

Configure SFTPPlus MFT

Prerequisites

  • This guide assumes that SFTPPlus MFT is already installed and operational in your environment.
  • The integration procedures described in this guide are platform-independent and apply to SFTPPlus MFT deployments running on Windows, Linux, macOS, Docker, Kubernetes, and other supported platforms.

The integration described in this guide demonstrates how to authenticate Windows domain users using their username and password, and then perform RSA SecurID token validation as an additional authentication method.

Procedure

  1. In the SFTPPlus management interface, create a new RADIUS Authentication Method.
  2. Configure the authentication method to connect to the AM RADIUS server.
  3. Enable the authentication method and configure it to be used as second-factor authentication.

    

Configure Windows Domain Authentication

Configure SFTPPlus to perform first-factor authentication against the Windows Domain users together with second-factor authentication via AM.

  1. Create a new Operating System Authentication Method in SFTPPlus.
  2. Configure the authentication method to authenticate users against the Windows domain.
  3. Restrict access to specific Windows groups by configuring the appropriate group membership settings. This ensures that only authorized domain users can access SFTPPlus file transfer services.
  4. Verify that second-factor authentication remains enabled for this authentication method.

  

Validate the Integration

  1. Sign in to SFTPPlus using an SFTP client.
  2. When prompted, enter your Windows domain username and password.
  3. After the primary credentials are successfully validated, enter your RSA SecurID token when prompted.

Successful validation of both factors confirms that SFTPPlus is authenticating users through the Windows domain and AM.

The following is an example of an SFTP session authentication interaction. 

$ sftp -P 10022 win-ad-user@sftpplus.acme.com
Welcome to ACME Inc SFTP Service
RSA SecurID MFA required
(win-ad-user@sftpplus.acme.com) Domain password>
More credentials required
First factor accepted. Second factor required.

(win-ad-user@sftpplus.acme.com) RSA AuthMan v8.7.1:

Note: SFTPPlus supports the creation of multiple user groups, allowing you to assign different levels of file transfer access and permissions based on group membership.

The configuration is complete.