The IDaaS ISAPI Filter solution provides strong second-factor authentication to Microsoft Outlook Web Access (OWA), Remote Desktop Web Access (RD Web Access), Integrated Windows Authentication (IWA), SharePoint, and generic TMG forms-based authentication types. The solution is made up of two components: the filter component and the authentication application component.
Users logging in to ISAPI must complete two authentication challenges. For first-factor authentication, use one of the ISAPI default authentication methods listed in the table below (such as entering an ISAPI account password).
ISAPI supports the following first-factor authentication methods:
ISAPI authentication method |
Identity as a Service authentication method |
ISAPI first-factor authentication |
Based on the Identity as a Service Resource Rule. Note: Skip Password is not supported. It must be set to Password or External. |
Entrust password authentication |
Password |
Outlook Web Access (OWA) authentication |
EXTERNAL |
Remote forms-based authentication |
EXTERNAL |
Integrated Windows authentication |
EXTERNAL |
External authentication |
EXTERNAL |
The following authenticators are supported for second-factor authentication:
● Token (software and hardware)
● Push notification
● One-time password
● Grid
● Temporary Access Code
● Knowledge-based authentication
Note: This integration provides the instructions to add Entrust ISAPI Filter to Identity as a Service. For legacy versions of Entrust IdentityGuard ISAPI Filter, see Integrate Entrust IdentityGuard ISAPI Filter.
Integrate ISAPI Filter
1. To complete this procedure, you need to reference the Entrust ISAPI Filter 13.0 Technical Integration Guide.
Note: To ensure that you are using the latest version of the document, it is best to download the document from Entrust TrustedCare.
2. Add
IDaaS ISAPI Filter to Identity as a Service.
3. Be sure to copy the Application ID. You need this ID to complete the installation of the ISAPI Filter for Identity as a Service.
4. Protect
IDaaS ISAPI Filter with a resource rule.
Note: When used for OWA protection, the ISAPI module requires that the first factor be set to External in the Identity as a Service Resource Rule. If this is set to Skip Password or Password, the user authentication from OWA will fail.
5. Using the Entrust ISAPI Filter documentation, complete the following:
a. Install the Entrust ISAPI Filter (see the section Installing the Entrust ISAPI Filter).
b. Configure ISAPI or Identity as a Service (see the section, Configuring ISAPI Filter for Identity as a Service).