Setting up Two-Factor Authentication (TFA) - PhoneFactor Authentication14 minutes to read
ManageEngine has partnered with PhoneFactor, the leading global provider of phone-based TFA, to enable simple, effective two-factor security for PAM360. ManageEngine is a PhoneFactor Alliance Partner and offers seamless integration with PhoneFactor's authentication services. PhoneFactor works by placing a confirmation call to your phone during the login process. Upon completing your first authentication through usual means and when you go to the second authentication stage, you simply need to answer your phone and press # (or enter a PIN), which serves as the phone-based authentication. The following topics are discussed in this document:
1. How Does PhoneFactor Work with PAM360?You will be specifying the phone numbers for your users, which results in a mapping between the users and the corresponding phone numbers. In PhoneFactor agent mode, the details about the user, including the phone numbers are maintained at the agent. In Direct SDK mode, the phone numbers are maintained in PAM360 database itself. When a user tries to login to PAM360, PhoneFactor finds out the phone number of the respective user and triggers a call. 2. Sequence of Events
3. Enabling PhoneFactor Authentication3.1 PrerequisitePrior to enabling PhoneFactor authentication, you need to buy PhoneFactor. Refer to PhoneFactor website for details. After getting PhoneFactor, you need to decide about the specific authentication method - whether you want to install PhoneFactor agent in your environment or deploy PhoneFactor Direct SDK. 3.2 Setting up TFA in PAM360
Note: Before proceeding further, ensure that you have entered the phone numbers for all the users for whom you wish to enable TFA through PhoneFactor in PAM360. You can enter a landline number or a mobile number as the primary contact number for PhoneFactor authentication. 3.3 Deciding the type of PhoneFactor AuthenticationYou can choose to deploy PhoneFactor Agent or PhoneFactor Direct SDK. 3.3.1 Configurations in PhoneFactor AgentThe PhoneFactor agent runs on a Windows server within your network. It includes a configuration wizard that guides you through the setup process for securing PAM360 with PhoneFactor. The PhoneFactor agent can also integrate with your existing Active Directory or LDAP server for centralized user provisioning and management. All user data is stored within the corporate network for additional security. Extensive logging is available for reporting and auditing. Obtain and install the PhoneFactor Agent and Web Services SDK on a Windows server within your network. The wizard will guide you through the installation process. 1. Configurations in PhoneFactor
Important Note: User information and their phone numbers are maintained in PhoneFactor agent. That means, users will receive the call only at the phone numbers specified in the agent. Whenever, you want to modify the phone number, you need to carry out the change at the agent. Similarly, whenever you add new users to PAM360 and if TFA through PhoneFactor is enabled for them, you need to add the user in PhoneFactor agent too. Otherwise, TFA through PhoneFactor will not work. 2. Configurations in PAM360
While installing the PhoneFactor agent/ Web Services SDK, you would have either created a self-signed SSL certificate or you would have used an already available internal certificate (your own certificate). Here, in PAM360, you need import the root of the CA. If you are using a certificate signed by third-party CA, you may skip this step.
Steps to Import the Root of the CA:
Note: If your enterprise network setup requires connecting to the internet via a proxy server, you need to configure the proxy settings to enable PAM360 connect to PhoneFactor website. (PAM360 console >> Admin >> General >> Proxy Server Settings)
| |