ESET Secure Authentication On-Prem – Table of Contents

Using ESET Secure Authentication On-Prem

Authentication options

oMobile Application

oPush Authentication

oHard Tokens

oFIDO

oDelivery options

Sample PowerShell scripts

SMTP Settings

Credential providers supported by ESA

Windows Login Protection

Identity Provider Connector

oConfigure Identity Provider Connector in ESA Web Console

oIdP Connector Configuration Examples

Master recovery key

RADIUS server and VPN Protection

oRADIUS Configuration

oRADIUS Usage

oVPN Authentication Options

SMS-based OTPs

On-demand SMS-based OTPs

Mobile Application

Hard Tokens

Migration from SMS-Based OTPs to Mobile Application

Non-2FA Pass-through

Access Control Using Group Membership

oESA Authentication Methods and PPP Compatibility

oVerifying ESA RADIUS functionality

Ensure your ESA RADIUS Service is running

Configure your RADIUS Server

Verify functionality (localhost)

Verify network connectivity from another machine (optional)

Troubleshooting

RADIUS PAM modules on Linux/Mac

oCreate ESA RADIUS clients via API

oPAM configuration

oOther RADIUS configurations

Web Application Protection

oConfiguration

oUsage

Remote Desktop Protection

oConfiguration

oAllowing Non-2FA Users

oUsage

oRemote Desktop Web Access

oRemote Desktop Gateway and ESA RADIUS

IP address whitelisting

AD FS

oAD FS Policies

Custom ESA Service Account

Custom integration via API and SDK

oAPI

Integration Overview

Configuration

oSDK

Integration Overview

SDK License Activation

SDK in practice

Using the SDK

SDK System Integration

Additional Components

oSummary of differences

Auditing and Licensing

oReports

oAuditing

oSubscription Overview

oSubscription States

MSP options