Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

There may be a requirement to protect a PC that is not joined to the domain or even connected to the same network.  We have a solution for this.  It is fairly easy to set up, but there are a few extra prerequisites needed in order to get this working

Prerequisites

...

bordertrue
Column

Make a note of the host name of the computer.  In this case it is 'ABC'

...

width60%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed Image Removed

...

bordertrue

...

Create some local user accounts and make sure the Administrator account is active.

...

width60%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Create a Virtual Domain

...

bordertrue
Column

Login to the DualShield Administration Console and go to Identity>Identity Sources

Click on Image Removed on the top right.

It is recommended to specify the hostname of the Non-Domain joined machine as the friendly name of this identity source.

Also, make sure the Type is set to SQL

Click Finish

...

width60%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

In the Logon Steps Dialogue box, click the Image Removed button.

...

bordertrue
Column

Tick the desired authentication method, e.g. Static Password

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Click Save.

...

bordertrue
Column
I have added two steps; Static Password and One-Time Password

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

 Image Removed

Create an Application

...

bordertrue
Column

Authentication> Applications

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Click on Image Removed on the top right.

...

bordertrue

...

Please note: For initial set up the machine must be connected to the same network even if it is not joined to the domain.

Children Display

In the new Application window, please enter the following information:

...

Select the Logon Procedure you had created in the previous step

Click: Save

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Bind the Application to an SSO Server Agent

...

bordertrue
Column

Select the drop down menu corresponding to the Application you will be using and click on Agents.

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

...

bordertrue
Column

Tick the box of the SSO Server you will be using and click Save below.

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Create a Service Provider Profile

...

bordertrue
Column

Go to SSO>Service Providers

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Click on Image Removed on the top right.

...

bordertrue
Column

Fill in the details as per screenshot on right and make sure you select SAML 2.0(Without Metadata) as Type.

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

...

bordertrue

...

Now fill out Entity ID and ACS URL.

...

...

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

...

bordertrue
Column

The completed Service Provider dialogue box will look like this:

...

width50%
Panel
borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

Image Removed

Click Save.

...

bordertrue

Download the IDP Metadata file.

...

bordertrue
Column

Go to SSO>SSO Servers

...

width50%

...

bordertrue
Column

Select the drop down menu corresponding to the SSO server you will be using and click on Download IDP Metadata.

...

width50%

...

borderColor#9EBEE5
bgColor#f0f0f0
borderWidth1px

...