Secure Mobile Access 12.5 Administration Guide

Table of Contents

Configuring One Identity Defender with User or Token-Based Credentials

Defender is a product for 2-factor authentication. SMA supports One Identity Defender configuration as a generic RADIUS server.

To configure a new Authentication Server with One Identity Defender

  1. In the AMC, navigate to System Configuration > Authentication Servers.

  2. Click on New.

  3. Select the One Identity Defender (Username/Password) or (Token/SecurID) option.

  4. In the Name field, enter a name for the authentication server.

  5. In the Primary Defender server field, enter the IP address of the primary defender server.

  6. In the Secondary Defender server field, enter the IP address of the secondary defender server.

  7. In the Shared Secret field, enter your shared secret.

  8. From the Match Defender user groups by drop-down menu, select:

    • None (default)

    • filterid attribute (11)

    • class attribute (25)

  9. In the Connection timeout field, enter the connection timeout value, in seconds.

  10. To change the prompts and other text that Windows users see when they log in to the authentication server, select Customize authentication server prompts. The page title, message, and login prompts can all be customized. For example, if a user logs in using his employee ID, you could change the text for the Identityprompt from Username: to Employee ID:

  11. To enable NTLM authentication forwarding, click one of the NTLM authentication forwarding options. For more information, see NTLM Authentication Forwarding.
  12. Click Save.