- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Two-Factor support for admin and self-service console?
My management is a bit bummed by the fact that even though we have converted a large percentage of our user accounts from username/password to 2-factor via the SecurID token, the management of these servers still relies on username and password. We still have to issue a password to users so they can manage their PINs. Since we are in a DoD environment and everyone has a CAC/PIV, isnt there some way to integrate this into the admin and self-service consoles?
- Tags:
- 2fa
- admin console
- AM
- Auth Manager
- Authentication Manager
- authentication methods
- cac
- Community Thread
- Discussion
- Forum Thread
- pki
- RSA Authentication Manager
- RSA SecurID
- RSA SecurID Access
- SecurID
- SecurID Token
- security console
- self-service console
- two factor
- two-factor
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To edit the authentication methods for the Security Console, login to the Security Console and select Setup > System Settings. Under Console & Session Handling, click Security Console Authentication Methods. From there you can select one or more authentication methods for accessing the Self-Service Console. These are RSA Password, LDAP Password, SecurID Native (that is, a tokencode or passcode) and/or OnDemand. Note that the different methods can be joined with various operators.
For more information, be sure to click on the Help on this page link in the Security Console and review the information on how to configure Security Console Authentication Methods. Before making such configuration changes, please do pay attention to the note on the page. You don't want to accidentally lock out your administrators.
To edit the authentication methods for the Self-Service Console, from the Security Console, select Setup > Self-Service Settings. Under Customization, click on Self-Service Console Authentication. From there you can select one or more authentication methods for accessing the Self-Service Console. As with the Security Console, these are RSA Password, LDAP Password, SecurID Native (that is, a tokencode or passcode) and/or OnDemand. Again, the different methods can be joined with various operators.
For more information, be sure to click on the Help on this page link in the Security Console and review the information on how to set the Authentication Method for the Self-Service Console.
Regards,
Erica
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. Security Console Authentication Methods allows you to remove the password and require
token or on-demand token or any combo. Use the help menu for specific details.
Operations Console cannot use tokens, passwords only for this web interface.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To edit the authentication methods for the Security Console, login to the Security Console and select Setup > System Settings. Under Console & Session Handling, click Security Console Authentication Methods. From there you can select one or more authentication methods for accessing the Self-Service Console. These are RSA Password, LDAP Password, SecurID Native (that is, a tokencode or passcode) and/or OnDemand. Note that the different methods can be joined with various operators.
For more information, be sure to click on the Help on this page link in the Security Console and review the information on how to configure Security Console Authentication Methods. Before making such configuration changes, please do pay attention to the note on the page. You don't want to accidentally lock out your administrators.
To edit the authentication methods for the Self-Service Console, from the Security Console, select Setup > Self-Service Settings. Under Customization, click on Self-Service Console Authentication. From there you can select one or more authentication methods for accessing the Self-Service Console. As with the Security Console, these are RSA Password, LDAP Password, SecurID Native (that is, a tokencode or passcode) and/or OnDemand. Again, the different methods can be joined with various operators.
For more information, be sure to click on the Help on this page link in the Security Console and review the information on how to set the Authentication Method for the Self-Service Console.
Regards,
Erica
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, Erica! That is quite helpful!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good Morning,
We are having the same difficulty. Our Organization is beginning to roll out the Alternate Token Cards (ATC) for administrative accounts. So our "Administrators" won't technically have a password anymore and be forced to use their Token for Privilege elevation.
I will need the RSA Authentication Manager Self Help Portal to be able to pass the credentials of the logged in user and/or prompt for a Certificate for authentication to LDAP.
I have put a support ticket in to assist. However, i am wondering if anyone else got this working?
Thank you
