Integrate Identity as a Service ISAPI Filter

The IDaaS ISAPI Filter solution provides strong second-factor authentication to Microsoft Outlook Web Access (OWA), Remote Desktop Web Access (RD Web Access), Integrated Windows Authentication (IWA), SharePoint, and generic TMG forms-based authentication types. The solution is made up of two components: the filter component and the authentication application component.

Users logging in to ISAPI must complete two authentication challenges. For first-factor authentication, use one of the ISAPI default authentication methods listed in the table below (such as entering an ISAPI account password).

ISAPI supports the following first-factor authentication methods:

ISAPI authentication method

Identity as a Service authentication method

ISAPI first-factor authentication

Based on the Identity as a Service Resource Rule.

Note: Skip Password is not supported. It must be set to Password or External.

Entrust password authentication

Password

Outlook Web Access (OWA) authentication

EXTERNAL

Remote forms-based authentication

EXTERNAL

Integrated Windows authentication

EXTERNAL

External authentication

EXTERNAL

 The following authenticators are supported for second-factor authentication:

       Token (software and hardware)

       Push notification

       One-time password

       Grid

       Temporary Access Code

       Knowledge-based authentication

Note:  This integration provides the instructions to add Entrust ISAPI Filter to Identity as a Service. For legacy versions of Entrust IdentityGuard ISAPI Filter, see Integrate Entrust IdentityGuard ISAPI Filter.

Integrate ISAPI Filter

1.      To complete this procedure, you need to reference the Entrust ISAPI Filter 13.0 Technical Integration Guide.

Note: To ensure that you are using the latest version of the document, it is best to download the document from Entrust TrustedCare.

2.      Add IDaaS ISAPI Filter to Identity as a Service.

3.      Be sure to copy the Application ID. You need this ID to complete the installation of the ISAPI Filter for Identity as a Service.

4.      Protect IDaaS ISAPI Filter with a resource rule.

 

Note: When used for OWA protection, the ISAPI module requires that the first factor be set to External in the Identity as a Service Resource Rule. If this is set to Skip Password or Password, the user authentication from OWA will fail.

5.      Using the Entrust ISAPI Filter documentation, complete the following:

a.      Install the Entrust ISAPI Filter (see the section Installing the Entrust ISAPI Filter).

b.      Configure ISAPI or Identity as a Service (see the section, Configuring ISAPI Filter for Identity as a Service).