Windows Azure Multi-Factor Authentication



Similar documents
Multi-factor Authentication using Radius

Browser-based Support Console

Host Installation on a Terminal Server

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Defender Token Deployment System Quick Start Guide

Installing the ASP.NET VETtrak APIs onto IIS 5 or 6

Fax User Guide 07/31/2014 USER GUIDE

SafeWord Domain Login Agent Step-by-Step Guide

Tenrox. Single Sign-On (SSO) Setup Guide. January, Tenrox. All rights reserved.

Distributing SMS v2.0

Installation and Configuration Guide

ACTIVE DIRECTORY DEPLOYMENT

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

Aspera Connect User Guide

Your Archiving Service

How To Install Ctera Agent On A Pc Or Macbook With Acedo (Windows) On A Macbook Or Macintosh (Windows Xp) On An Ubuntu (Windows 7) On Pc Or Ipad

HOW TO SILENTLY INSTALL CLOUD LINK REMOTELY WITHOUT SUPERVISION

Customer Tips. Configuring Color Access on the WorkCentre 7328/7335/7345 using Windows Active Directory. for the user. Overview

SchoolBooking SSO Integration Guide

Verify LDAP over SSL/TLS (LDAPS) and CA Certificate Using Ldp.exe

Configuring Color Access on the WorkCentre 7120 Using Microsoft Active Directory Customer Tip

Desktop Surveillance Help

Schools Remote Access Server

SecureAware on IIS8 on Windows Server 2008/- 12 R2-64bit

Remote Viewer Recording Backup

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

Wavecrest Certificate

ESET SECURE AUTHENTICATION. API SSL Certificate Replacement

How To Enable A Websphere To Communicate With Ssl On An Ipad From Aaya One X Portal On A Pc Or Macbook Or Ipad (For Acedo) On A Network With A Password Protected (

1/4/12 Installing and Configuring WebDAV on IIS 7 : WebDAV for IIS 7.0 : Publishing Content to Web Sites : T

Getting Started with the Ed-Fi ODS and Ed-Fi ODS API

Installation Logon Recording Basis. By AD Logon Name AD Logon Name(recommended) By Windows Logon Name IP Address

BusinessObjects Enterprise XI Release 2

Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide

Appendix E. Captioning Manager system requirements. Installing the Captioning Manager

etoken Enterprise For: SSL SSL with etoken

Ascend Interface Service Installation

Setup Guide for AD FS 3.0 on the Apprenda Platform

Sage HRMS 2014 Sage Employee Self Service Tech Installation Guide for Windows 2003, 2008, and October 2013

Installation Guide. SafeNet Authentication Service

Ekran System Help File

Install the Production Treasury Root Certificate (Vista / Win 7)

Security Guidelines for MapInfo Discovery 1.1

IIS, FTP Server and Windows

IMDG Code for Intranet

pcanywhere Advanced Configuration Guide

McAfee One Time Password

Moodle Administrator s Manual Table of Contents

Configuring Windows 7 to Use Encrypted (WPA-E) Wireless Services a...

Cloud Attached Storage

Installing Policy Patrol on a separate machine

Compiled By: Chris Presland v th September. Revision History Phil Underwood v1.1

IISADMPWD. Replacement Tool v1.2. Installation and Configuration Guide. Instructions to Install and Configure IISADMPWD. Web Active Directory, LLC

Alert Notification of Critical Results (ANCR) Public Domain Deployment Instructions

Advanced Configuration Steps

Administration Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

How to Move an SAP BusinessObjects BI Platform System Database and Audit Database

INSTALLATION GUIDE Netop Mobile for Android

Using RD Gateway with Azure Multifactor Authentication

Setting up Sharp MX-Color Imagers for Inbound Fax Routing to or Network Folder

User Setup for SQL Security

SafeNet Authentication Service

NETASQ SSO Agent Installation and deployment

Setting Up a Unisphere Management Station for the VNX Series P/N Revision A01 January 5, 2010

Integrating LANGuardian with Active Directory

Entrust Managed Services PKI. Configuring secure LDAP with Domain Controller digital certificates

Sitecore Ecommerce Enterprise Edition Installation Guide Installation guide for administrators and developers

Netop Remote Control Security Server

How to Configure a Secure Connection to Microsoft SQL Server

4cast Server Specification and Installation

Set Up Setup with Microsoft Outlook 2007 using POP3

Protected Trust Directory Sync Guide

Configuring Claims Based FBA with Active Directory store 1

ELM Server Exchange Edition Virtual Archive Mailbox version 5.5

RSA Authentication Manager 7.1 Basic Exercises

How To Create An Easybelle History Database On A Microsoft Powerbook (Windows)

ION EEM 3.8 Server Preparation

WhatsUp Gold v16.2 Installation and Configuration Guide

Setting up VMware ESXi for 2X VirtualDesktopServer Manual

Aventail Connect Client with Smart Tunneling

Copyright 2012 Trend Micro Incorporated. All rights reserved.

3. Viewing and Restoring Items and Files from the Mimosa Archive

Introduction. Before you begin. Installing efax from our CD-ROM. Installing efax after downloading from the internet

RSA Security Analytics

EM L12 Symantec Mobile Management and Managed PKI Hands-On Lab

STATISTICA VERSION 10 STATISTICA ENTERPRISE SERVER INSTALLATION INSTRUCTIONS

SOLGARI CLOUD BUSINESS COMMUNICATION SERVICES CLOUD CONTACT CENTRE MICROSOFT DYNAMICS INTEGRATION

System Area Management Software Tool Tip: Integrating into NetIQ AppManager

NetWrix USB Blocker. Version 3.6 Administrator Guide

Windows Live Mail Setup Guide

ADFS Integration Guidelines

GFI Product Manual. Outlook Connector User Manual

PaperStream Connect. Setup Guide. Version Copyright Fujitsu

Installing SQL Express. For CribMaster 9.2 and Later

Installation and Configuration Guide

Install and configure SSH server

Quick Start Guide for VMware and Windows 7

Promap V4 ActiveX MSI File

Integration Guide. SafeNet Authentication Service. Oracle Secure Desktop Using SAS RADIUS OTP Authentication

ez Agent Administrator s Guide

Transcription:

Windows Azure Multi-Factor Authentication Netop develops and sells software solutions that enable swift, secure and seamless transfer of video, screens, sounds and data between two or more computers over the Internet. For more information, see www.netop.com.

Contents 1 Introduction... 2 2 Retrieve the Windows Azure information... 3 3 Configure the Host machine... 7 3.1 Apply the Windows Azure information... 7 3.2 Configure the Host... 12 4 Connect to the Host machine... 15 5 Troubleshoot... 17 5.1 I do not receive any text message.... 17 5.2 Error connecting to Host. Error = 100... 17 Copyright Netop 2014. All rights reserved 1

1 Introduction Netop Remote Control version 11.6 introduces extended security with Windows Azure multifactor authentication. The host is validated based on two factors: one authentication factor is the Host credentials (something the user knows), the second factor is a passcode received by phone (something the use has). This document explains how to retrieve the Microsoft Azure information, how to configure and connect to the host. Copyright Netop 2014. All rights reserved 2

2 Retrieve the Windows Azure information 1. Sign up for a Windows Azure account (link) or use your existing Windows Azure account and login (link). 2. Go to Portal. 3. Go to ACTIVE DIRECTORY > MULTI-FACTOR AUTH PROVIDERS and click CREATE A NEW MULTI-FACTOR AUTHENTICATION PROVIDER. 4. Configure a name and select the Usage model. You can also link to a directory (not mandatory). Click CREATE. Copyright Netop 2014. All rights reserved 3

5. Click the Manage icon located at the bottom of the page. 6. Go to Downloads > SDK. Copyright Netop 2014. All rights reserved 4

7. Download the zip version of ASP.NET 2.0 C# and unarchive it. Open the pf folder from the archive. 8. Open the pf_auth.cs file in a text editor (preferably a more advanced text editor like Word Pad). Look for CERT_PASSWORD. This represents the password for the certificate that will be used on the Host device. Copyright Netop 2014. All rights reserved 5

In the pf > certs folder you can find the certificate. The certificate and the password for the certificate represent the 2 items required from the Windows Azure account. Copyright Netop 2014. All rights reserved 6

3 Configure the Host machine 3.1 Apply the Windows Azure information In order for the machine to use the Windows Azure multi factor authentication, it needs to be securely identified by Windows Azure. This is done by installing the Certificate obtained previously. The steps below are for installing the Certificate on a Windows 7 machine. This can be done also using various mass deployment techniques (e.g.: Group Policy). 1. Run mmc.exe in order to install the certificate. 2. Click File > New. Then click File> Add/Remove Snap-in Copyright Netop 2014. All rights reserved 7

3. Choose Certificates and click Add Copyright Netop 2014. All rights reserved 8

4. Choose Computer account and click Next. 5. Choose Local computer, click Finish then click OK. Copyright Netop 2014. All rights reserved 9

6. Click OK and go to Certificates > Personal. Right-click and choose All Tasks > Import 7. Click Next. Click Browse and go to the unarchived folder and open the pf > certs folder. Make sure All files is selected in the drop-down filter. Select the cert_key.p12 file. 8. Click Next. Fill in the certificate password retrieved at Step 8. Copyright Netop 2014. All rights reserved 10

9. Click Next, then click Finish. 10. Click Next. Make sure the Personal store is selected. Copyright Netop 2014. All rights reserved 11

11. Click Next and then Finish. The certificate is now installed and it should appear in the Personal folder. 3.2 Configure the Host 1. Make sure the Netop Remote Control Host version 11.6 is installed. 2. Go to Tools > Program Options > Multi-Factor Services. This area allows you to add multiple multi-factor authentication services. Note: Once defined in this area they can be applied to different role groups as presented below. Copyright Netop 2014. All rights reserved 12

3. Click Add. Provide the service a name. Select Windows Azure Multi-Factor for the Multi-Factor Service Type. Choose the certificate that was previously installed under Client Certificate. The LDAP Phone No Attribute identifies the user's telephone number. It will be used to send user the token to be used for multi-factor authentication. Select the Apply to all roles check box to apply the multi-factor authentication to all roles defined in the Directory Services. Note: Multi-factor authentication applies to all roles only if the Guest Access Method selected from Tools > Guest Access Security is either Grant each Guest individual access privileges using Windows Security Management or Grant each Guest individual access privileges using Directory services. 4. Click Ok and then OK. This will finalize the configuration of the authentication service on the Host machine. 5. In order to associate the service with actual users, go to Tools > Guest Access Security. If Directory Services or Windows Management is used, a new area is displayed under the access privileges area. Copyright Netop 2014. All rights reserved 13

This allows enabling/disabling of the Multi-Factor Authentication services per role. Copyright Netop 2014. All rights reserved 14

4 Connect to the Host machine Make sure that the Guest is updated to the 11.6 version. 1. Connect to the device by filling in the credentials 2. A passcode will be sent to your mobile phone. Fill in the passcode. Copyright Netop 2014. All rights reserved 15

The remote session has started Copyright Netop 2014. All rights reserved 16

5 Troubleshoot 5.1 I do not receive any text message. 1. Check the Usage report in the Manage area. Generate a report for that timeframe and then go to Queued area and see if the message has been sent. 2. Check the phone number. It should not contain any spaces. 5.2 Error connecting to Host. Error = 100 After filling in the credentials, I get a message similar to this: Error connecting to Host. Error = 100. 1. Double-check the Windows Azure information. Make sure that the certificate you downloaded and the password are correct. 2. Check I do not receive any text message. Copyright Netop 2014. All rights reserved 17