Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Section
bordertrue


Column

Click on  on the top right.

Set these Values in the Policy - New Window

OptionValue
Category:

Windows Offline

Holder:

Domain

Domain:Enter the virtual domain name
Name:Enter a user-friendly name
Enabled:True

Check Enforce MFA on Local Computer Logon and Download Offline Tokens Automatically



Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px



Save the new Windows Offline policy

It is also recommended to exempt at least one local account from MFA (usually the local administrator account)  just in case there is an issue that prevents the end user from being able to log on, the administrator will still have access without being challenged.

Section
bordertrue


Column

Click on Image Added on the top right.

Set these Values in the Policy - New Window

OptionValue
Category:

Logon

Holder:

User

Domain:Enter the virtual domain name
User:Enter the name of the account you wish to exempt (e.g Administrator) 
Name:Enter a user-friendly name
Enabled:True
The completed Service Provider dialogue box will look like this:



Column
width50%60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image RemovedImage Added

Click Save.




Section
bordertrue

Download the IDP Metadata file.

...

bordertrue
Column

Go to SSO>SSO Servers

...

width50%

...


Column

Expand Authentication and select  MFA is not required for all users from the drop down,


Column
width60%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Added





Save the new Logon policy.


Section
bordertrue


Column

Select the drop down menu corresponding to the SSO server you will be using and click on Download IDP Metadata.


Column
width50%


Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px



...