Answered TMG - SMS 2 factor

  • Thursday, November 22, 2012 4:32 PM
     
     

    Hi

    Have a simple question. I have done this in the UAG, where a use a SMS as 2 factor. First the user is prompted for username/password, and after that a new page loads where they are prompted for a SMS/Token etc. (for OWA)

    Is the same thing possible for the TMG, or do I need to custom design the second page?

All Replies

  • Thursday, November 22, 2012 5:02 PM
    Moderator
     
     Answered
    TMG has native support for OTP so the forms have the ability to provide additional form fields to enter OTP information. It is also not uncommon for authentication vendors (Swivel for example) to provide custom TMG forms which add capabilities for their particular solution...

    Jason Jones | Microsoft MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk

  • Thursday, November 22, 2012 5:59 PM
     
     

    Ok, as far as I can get the TMG to do, is to provide the additional fields on the first login page, so that the user is prompted for username/password and passcode. Currently I have set Authentication Delegation to Basic. On the Listener -> Authentication is set to HTML Form authentication and there is a mark in Collect additional credentials. And set a mark in Radius OTP and configured the radius server. The radius part should work, since the same setup work on UAG.

    How could i set it up, to use the native OTP support in the TMG, if it has a "second" page to enter the OTP on. ( I am using Pointsharp at the moment, if that information is important)

  • Thursday, November 22, 2012 7:54 PM
    Moderator
     
     
    I don't see why you would want a second page if you can enter all your details into a single form page?? If using Pointsharp, don't they have any specific guidance for integrating their solution with TMG?

    Jason Jones | Microsoft MVP | Silversands Ltd | My Blogs: http://blog.msedge.org.uk and http://blog.msfirewall.org.uk