Symantec Access Management

  • 1.  Extending CA Strong Authentication to achieve Operating System 2FA

    Posted Oct 19, 2017 11:23 PM

    We currently have CA AuthMinder v8.0.1 installed in our environment. It is currently configured for Arcot ID PKI. This implementation support browser based 2F authentication. We have a requirement Extending CA Strong Authentication to achieve Operating System 2FA, where in user will be asked for 2FA when trying to RDP into a server. Is this implementation possible with our existing Arcot ID PKI implementation? 



  • 2.  Re: Extending CA Strong Authentication to achieve Operating System 2FA
    Best Answer

    Broadcom Employee
    Posted Oct 20, 2017 06:35 AM

    We have a component named 'Strong Authentication for Windows Login', which provides  2-factor Authentication during windows login. Following are some of the details about the component.

     

     

    What It Does

    This Packaged Work Product shall integrate CA Advanced Authentication with Microsoft Windows Server & Desktop and provide 2-factor Authentication during windows login.

    Benefits That Deliver Value

    • Single component which integrates with both Microsoft Windows Servers & Desktops.
    • Closely integrates with CA Advanced Authentication for CA AuthID/CA Mobile OTP and Step-up can be performed by OTP sent via email or SMS. CA Mobile OTP can be used as step-up authentication during offline windows logon.
    • Can differentiate (using Credential Provider) privileged windows accounts. So that step-up can be initiated only for privileged accounts (administrators) and not for non-privileged (normal users) accounts when they login.
    • Client components can be installed/uninstalled by the Admin user with appropriate access which can be enforced by GPO policies.
    • If the Windows Server/Desktop does not have network connectivity and/or CA Advanced Authentication servers are not reachable, the user will be authenticated per the process in place today, using cached AD password and CA Mobile OTP as 2-factor authentication.


  • 3.  Re: Extending CA Strong Authentication to achieve Operating System 2FA

    Posted Oct 20, 2017 10:50 AM

    Thanks Rajiv!

    Can you please point me to the documentation of the packaged Product? Will this work with v8.0.1 and Arcot ID PKI credential type?