Microsoft Office365 with Active Directory Federated Services (ADFS) Authenticating Users Using SecurAccess Server by SecurEnvoy



Similar documents
SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Windows 2003 Server with Routing and Remote Access service Authenticating Users Using SecurAccess Server by SecurEnvoy

ipad or iphone with Junos Pulse and Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Juniper SSL VPN appliance Authenticating Users Using SecurAccess Server by SecurEnvoy

How To Integrate Watchguard Xtm With Secur Access With Watchguard And Safepower 2Factor Authentication On A Watchguard 2T (V2) On A 2Tv 2Tm (V1.2) With A 2F

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Citrix Access Gateway Advanced Edition

Microsoft Outlook Web Access 2013 Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Windows 2012 R2 Server with Remote Desktop Web Gateway Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Cisco VPN 3000 Concentrator Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Netscreen 25 Remote VPN Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Fortinet Fortigate UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

External authentication with Astaro AG Astaro Security Gateway UTM appliances Authenticating Users Using SecurAccess Server by SecurEnvoy

Dell SonicWALL and SecurEnvoy Integration Guide. Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with CiscoSecure ACS. Authenticating Users Using. SecurAccess Server. by SecurEnvoy

External Authentication with Windows 2008 Server with Routing and Remote Access Service Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Checkpoint R75.40 Authenticating Users Using SecurAccess Server by SecurEnvoy

External Authentication with Cisco ASA Authenticating Users Using SecurAccess Server by SecurEnvoy

Full disk encryption with Sophos Safeguard Enterprise With Two-Factor authentication of Users Using SecurAccess by SecurEnvoy

Compiled By: Chris Presland v th September. Revision History Phil Underwood v1.1

SecurEnvoy IIS Web Agent. Version 7.2

HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services

Microsoft Office 365 with ADFS

External Authentication with Cisco Router with VPN and Cisco EZVpn client Authenticating Users Using SecurAccess Server by SecurEnvoy

SecurEnvoy Windows Login Agent

SSH to Ubuntu Server Authenticating Users Using SecurAccess Server by SecurEnvoy

HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services

HOTPin Integration Guide: Google Apps with Active Directory Federated Services

HOTPin Integration Guide: DirectAccess

ADFS Integration Guidelines

Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization

SecurEnvoy Reporting Wizard

Defender Token Deployment System Quick Start Guide

Multi-factor Authentication using Radius

SharePlus Enterprise: Security White Paper

Deploying RSA ClearTrust with the FirePass controller

ZyWALL OTP Co works with Active Directory Not Only Enhances Password Security but Also Simplifies Account Management

Swivel Secure and the Cloud

SecurEnvoy Security Server Installation Guide

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Step by Step Guide to implement SMS authentication to F5 Big-IP APM (Access Policy Manager)

OneLogin Integration User Guide

Mod 2: User Management

Owner of the content within this article is Written by Marc Grote

icrosoft TMG Replacement with NetScaler

Integration Guide. Duo Security Authentication

Setup Guide: Server-side synchronization for CRM Online and Exchange Server

Implementation Guide for. Juniper SSL VPN SSO with OWA. with. BlackShield ID

Passwordstate Mobile Client Manual Click Studios (SA) Pty Ltd

Dell One Identity Cloud Access Manager How to Configure Microsoft Office 365

DualShield Authentication Platform

360 Online authentication

NSi Mobile Installation Guide. Version 6.2

Cloud Authentication. Getting Started Guide. Version

WatchDox SharePoint Beta Guide. Application Version 1.0.0

Configuring Outlook for Windows to use your Exchange

iphone in Business How-To Setup Guide for Users

Configuring Sponsor Authentication

Cisco ASA. Implementation Guide. (Version 5.4) Copyright 2011 Deepnet Security Limited. Copyright 2011, Deepnet Security. All Rights Reserved.

Authentication Node Configuration. WatchGuard XTM

XIA Configuration Server

User Management Tool 1.5

Configure Single Sign on Between Domino and WPS

ZyWALL OTPv2 Support Notes

OVERVIEW. DIGIPASS Authentication for Office 365

USER GUIDE WWPass Security for Windows Logon

A brief on Two-Factor Authentication

Citrix Netscaler Advanced guide for SMS PASSCODE SMS PASSCODE 2014

QUICK SELLING GUIDE THE FUTURE OF AUTHENTICATION

INSTALLATION INSTRUCTIONS FOR UKSSOGATEWAY

Cloud Services for Backup Exec. Planning and Deployment Guide

BlackShield ID Best Practice

ADVANCED TWO-FACTOR AUTHENTICATION VIA YOUR MOBILE PHONE

Epic Remote Access for Mobile Devices FAQ and Setup

DESLock+ Basic Setup Guide Version 1.20, rev: June 9th 2014

Step-by-Step guide for SSO from MS Sharepoint 2010 to SAP EP 7.0x

Protecting Juniper SA using Certificate-Based Authentication. Quick Start Guide

Hosting topology SMS PASSCODE 2015

Authentication in XenMobile 8.6 with a Focus on Client Certificate Authentication

Security Assertion Markup Language (SAML) Site Manager Setup

DIGIPASS Authentication for Microsoft ISA 2006 Single Sign-On for Outlook Web Access

EMR Link Server Interface Installation

Mondopad v1.6. Quick Start

BlackShield ID Agent for Terminal Services Web and Remote Desktop Web

Entrust IdentityGuard Comprehensive

Preparing for GO!Enterprise MDM On-Demand Service

Agent Configuration Guide

Step by step guide to implement SMS authentication to Cisco ASA Clientless SSL VPN and Cisco VPN

Egnyte Single Sign-On (SSO) Configuration for Active Directory Federation Services (ADFS)

Managed Security Web Portal USER GUIDE

Configuring Single Sign-On from the VMware Identity Manager Service to Office 365

Lync Online Deployment Guide. Version 1.0

INTEGRATION GUIDE. DIGIPASS Authentication for Office 365 using IDENTIKEY Authentication Server with Basic Web Filter

Customer Tips. Configuring Color Access on the WorkCentre 7328/7335/7345 using Windows Active Directory. for the user. Overview

Strong Authentication for Microsoft SharePoint

Note that if at any time during the setup process you are asked to login, click either Cancel or Work Offline depending upon the prompt.

Cloud Services ADM. Agent Deployment Guide

Transcription:

Microsoft Office365 with Active Directory Federated Services (ADFS) Authenticating Users Using SecurAccess Server by SecurEnvoy Contact information SecurEnvoy www.securenvoy.com 0845 2600010 1210 Parkview Arlington Business Park Theale Reading RG7 4TY Andy Kemshall akemshall@securenvoy.com

This document describes how to integrate Microsoft s Online Services Office 365 configured for SSO to a local ADFS 2.0 service with SecurEnvoy two-factor Authentication solution called SecurAccess Microsoft Office 365 is a cloud based service that can be configured to use a local Active Directory Federation Service (ADFS) to enable local users to sign on with their existing AD credential to gain access to various Microsoft online services such as Office, SharePoint and Lync. SecurAccess provides two-factor, strong authentication for remote Access and cloud solutions (such as SSL VPN, IPSec VPN and Web authentication) from any device, without the complication of deploying hardware tokens or smartcards. Two-Factor authentication is provided by the use of (your PIN and your Phone to receive the one time passcode) SecurAccess is designed as an easy to deploy and use technology. It integrates directly into Microsoft s Active Directory and negates the need for additional User Security databases. SecurAccess consists of two core elements: a Radius Server and Authentication server. The Authentication server is directly integrated with LDAP or Active Directory in real time. All notes within this integration guide refer to this type of approach. The equipment used for the integration process is listed below Microsoft Office365 Cloud Account Microsoft Server 2008R2 with ADFS 2.0 Installed Optional (Microsoft Server 2008R2 with ADFS 2.0 Installed as a proxy) SecurEnvoy Windows 2003 server SP1 or Windows 2008 (any version) IIS installed with SSL certificate (required for management and remote administration) Active Directory installed SecurAccess software release v6.2

1.0 Prerequisites Is it expected that Office365 has already been setup for SSO to an onpremise ADFS server with working SSO based on users existing AD passwords. SecurEnvoy IIS Agent SecurEnvoy Server 2.0 Installation of SecurEnvoy Microsoft IIS Agent on ADFS The Microsoft IIS agent is located in the Agent directory of the software distribution Install this agent on your ADFS Proxy server(s) Note SecurEnvoy IIS Agent MUST be version 6.2 or higher Note If you do not use ADFS Proxy servers then install the agent on your ADFS server(s) Note If you have published ADFS through a reverse proxy such as UAG you should authenticate SecurEnvoy at this location. Refer to the relevant reverse proxy s integration guide

2.1 Configure IIS to protect ADFS Start the Microsoft IIS Manager Select Default web site under connections pane. Select the SecurEnvoy Icon Select Enable Authentication On Default Web Site.

Apply changes Under Default Web Site, expand adfs and select ls Select the SecurEnvoy Icon Select the check box Enable Authentication On /adfs/ls Note The virtual directory SecurEnvoyAuth MUST be a member of the ADFSAppPool

Navigate back to Default Web Site > adfs > ls and select the Authentication icon Make sure that only Basic Authentication is Enabled In the left side Navigation pane, select top level host name (the 2 nd line down). Scroll down the centre panel and press the SecurEnvoy Two Factor icon. Setup your required inactivity timeout. Add the logoff URL wsignoutcleanup Press Apply and restart IIS when prompted. wsignoutcleanup

3.0 Test Logon Open a browser and navigate to https://login.microsoftonline.com Enter a valid userid Select Sign in at (your domain name)

Enter a valid Microsoft password for this user Enter the passcode created by SecurEnvoy for this user