Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

When a web application is secured by the DualShield IIS Agent with MFA, the agent adds an extra layer of authentication process over the web applicationsapplication's own form-based authentication. Without the Single-Sign-On or Auto Logon, users will be firstly authenticated by both the DualShield SSO, then by the web application's orginal logon original login process which is usually the user's AD credential verification.

...

  1. Configure DualShield SSO to verifiy verify the 2nd factor only, e.g. one-time-password etc, and keep the application's orginal logon original login process which will verify the user's AD credentials. In this option. you do not need to enable Single Sign-On or Auto Logon. 
  2. Configure DualShield SSO to verifiy verify both the 2nd factor and the 1st factor. In this option. you will need to enable Single Sign-On or Auto Logon.  

...

Between Single Sign-On and Auto Logon options, Single Sign-On is preferred as it is easier to set up and quicker in performance. However, some IIS web servers have such restrictions so that it is not possible to enable Single Sign-On. 

...