2FA for ADFS

2FA for ADFS

A simple way to enforce 2FA for ADFS-integrated services

GreenRADIUS & ADFS 2FA Adapter

GreenRADIUS and our ADFS 2FA adapter can be deployed to enforce two-factor authentication for applications and resources integrated with ADFS.

Microsoft ADFS (Active Directory Federation Service) provides SSO (Single Sign On) for users to applications, services, and resources inside the organization, such as Web apps and disparate apps and resources, as well as SSO to Web services outside of their own organization, such as seamless access to Office 365, Google G-Suite, Slack, Salesforce.com, and more. Using a federated trust, ADFS manages user authentication via a proxy service hosted between Active Directory and the integrated applications and services. Users can then log into the federated application via SSO without the need to authenticate their identity directly on the application.

Features

Works with Active Directory, and nothing needs to be installed nor changed in Active Directory

Can also work with local user accounts on Windows PCs and servers

Works with domain-joined and non-domain-joined Windows PCs and servers

Users self-assign YubiKeys (either OTP or FIDO U2F) automatically upon first successful use

Windows Server OS

ADFS on Windows Server 2012 R2
ADFS on Windows Server 2016
ADFS on Windows Server 2019
Active Directory users and credentials

Supported Tokens

YubiKeys
Google Authenticator (or other similar Authenticator apps)

“Green Rocket 2FA” mobile app (which uses push notifications)

Possible ADFS Integrations

Microsoft 365 (formerly Office 365)
Google G-Suite
Slack
Salesforce.com
ZenDesk
Dropbox
Box
Citrix
Concur
Expensify
Zoom
WebEx
Marketo
Hubspot
Splunk
GitHub
NetSuite
QuickBooks Online
Stripe
Zenefits
Trello
Smartsheet
Any application or service that can be integrated with ADFS (such as integation via SAML 2.0)