ADSelfService Plus supports the following types of authenticators for VPN MFA:
One-way authenticators
Push Notification Authentication
Fingerprint/Face ID Authentication
These authenticators are automatically applicable for all the endpoints providing RADIUS authentication.
Challenge-based authenticators
ADSelfService Plus TOTP Authentication
Google Authenticator
Microsoft Authenticator
Yubico OTP (hardware key authentication)
SMS verification and email verification
Zoho OneAuth TOTP
PAP is configured for RADIUS authentication.
The RADIUS client (VPN or endpoint server) supports challenge-response; that is, it prompts a challenge (verification code) from the user and sends back the entered challenge.
VPN and other RADIUS clients | Supports one-way authenticators provided in ADSelfService Plus? | Supports challenge-based authenticators provided in ADSelfService Plus? |
Fortinet VPN | Yes | Yes |
OpenVPN Access Server (AS) | Yes | Yes |
Cisco ASA AnyConnect VPN | Yes | Yes |
NetMotion Mobility VPN | Yes | No |
Microsoft RDGateway | Yes | No |
Microsoft Routing and Remote Access Service (RRAS) | Yes | No |
Palo Alto VPN (GlobalProtect client) | Yes | Yes |
WatchGuard VPN | Yes | No |
Sonic Wall VPN | Yes | Yes |
Pulse Secure VPN | Yes | Yes |
Juniper | Yes | Yes |
Checkpoint | Yes | Yes |
VMWare Horizon | Yes | Yes |
ForcePoint | Yes | Yes |
Cisco Meraki | Yes | No |
Citrix/NetScaler Gateway | Yes | No |
Note: Status of authenticator availability may change in the future.