Revision 081716 HOW TO ENROLL AND USE REMOTE DESKTOP SERVICES
Contents Preamble & Prerequisites... 2 Enrollment Process... 3 Using Remote Gateway Services... 8 Preamble & Prerequisites How does Multi-Factor Authentication work? Multi-Factor Authentication works by placing a confirmation call or notifying the Multi-Factor Authentication mobile app during the login process to additionally validate your credentials. This is Multi-Factor Authentication. Page 2 of 13
This simple process provides two separate factors of authentication through two separate channels (your computer and your phone service). It works with any regular or mobile phone in phone call mode, or a device that supports the Multi-Factor Authentication mobile app (available from the app Store for your device). That s It! Step 1: Contact your LSO to get approval and begin the enrollment process. You will receive an email following approval with enrollment instructions. Step 2: Enter your usual username and password (Exchange LanID) into the Remote Desktop Application. Step 3: Instantly, you receive a phone call or a mobile app notification. For the phone call method, answer and enter your PIN followed by the #. For the mobile app method, enter your PIN or on select Apple devices your thumb print and press Authenticate in the Multi-Factor Authentication mobile app installed on your device. The following is required to utilize this service (Prerequisites): 1. A computer with Internet access using a current Windows Browser (IE or Chrome) NOT on the Exchange Network (Remote Computer). 2. A computer residing in an Exchange facility that has been registered for access by a remote user (destination Computer). 3. An Exchange User who is registered to use Remote Access Services to a particular registered computer (see #2) 4. A telephone or mobile device (Android or Apple) that is capable of receiving phone calls and entering numeric PINS or a mobile device that is capable of installing a mobile app. Data Service Charges may apply. Help information is available in the MFA User Portal if needed. Contact the Multi-Factor Administrator (multifactor@aafes.com) if you have further questions. For after-hours assistance, contact IT Help Desk Services or call 214.312.3800 option 2**. Enrollment Process FIRST SECOND Register your mobile device or phone with the Multi-Factor system Select the method you will use to receive & respond to Authentication requests. This is also where you provide your phone number (if you choose this method), backup phone number (if chosen) and your PIN. This is also where you install the Authentication app on your remote device if you choose this method. Page 3 of 13
LET S GET STARTED As a result of your processing your request for Remote Access through the IdM system via your Local Security Officer (LSO), you will receive an email to your Exchange account with information that will include a link to the MFA User Portal (https://mfa.aafes.com) and the PIN number that the system randomly generated for you. You are encouraged to change your PIN to a 6-Digit number that you can remember. Note: If you forget or need to reset your PIN, please contact the IT Helpdesk for assistance. 214.312.3800 option 2** Sample Email 1. By Clicking on the Portal link you will be taken to this page to begin. Supply the requested information and select Log IN. Page 4 of 13
2. Here you have the option to select the method that you wish to use for the system to notify you of Authentication requests. You can ONLY select one option and it is valid until you change it. You MUST install the Authentication app at this time on your remote device if that is the method you choose. (The remainder of this document assumes this is the option you have selected). If you choose the Phone Call Method, the screen will provide you with a place to register your Phone number and change your PIN. Details for this method are not included here (request support if needed). 3. If you choose the Microsoft Authentication app, you MUST install it on your remote device at this time. The system will allow you to register and install the app on up to 3 supported devices. Page 5 of 13
4. After you have selected the app and installed it, you MUST allow the device access to the Authenticator (app) and you MUST also provide the app access to your camera to scan the QR code. You can choose to disable this camera action after the code has been scanned (if you desire). Page 6 of 13
5. You are now ready to continue with the setup using both the MFA Portal and the mobile device. 6. Log into https://mfa.aafes.com using your LanID & LanPW. The following screen will appear. 7. Note: Once you are successfully registered and you return to this portal you will be MFA prompted. 8. Capture the QR code using the phone app Some cameras may not capture this QR code. If that happens, select the option to enter code manually and use the url & activation code listed next to the QR Page 7 of 13
9. Upon capture of the QR code in the app, you may see a success message and the page below will open. 10. In the app on the iphone your account will be registered as EXCHANGE with your LanID 11. Your MFA Account is now provisioned and you are enrolled. It is recommended that you change the PIN that was provided in the email to a 6-digit PIN you can remember. You can now use Remote desktop services Using Remote Gateway Services For users who are familiar with using Remote Desktop Services (formerly, tsgateway) before there is only one additional step you will encounter in this process and only one One-Time modification you need to make (tsgate.aafes.com becomes tsweb.aafes.com) in the Advanced > Settings tab. Page 8 of 13
1. On your Home or Remote computer, select the Remote Desktop application (mstsc) 2. Fill in the computer name and your LanID and LanPassword Page 9 of 13
3. In the Display tab choose your options 4. In the Advanced tab select Settings Page 10 of 13
5. In the Server Name: field type tsweb.aafes.com (this is the only configuration change for previous tsgateway users) 6. Return to the General tab and select Connect 7. You mat receive this Warning message. Check the box if you desire not to always see this. This is just a reminder warning Page 11 of 13
8. You will be prompted to enter your LanID Password (first factor) 9. At this point the connect will delay until you Authenticate with your MFA credentials (second factor) Page 12 of 13
10. At this point you will receive an authentication verify request on your Mobile App 11. Once you have authenticated successfully, the login process will continue. 12. You have successfully authenticated to your destination computer within the Exchange environment. Page 13 of 13