Start a new topic
Answered

Multi Factor Authentication

I am trying to provide multi factor authentication for my admins before they open Royal TS. 


Is there any knows MFA tools that work with this? We use Gemalto Safenet, but open to other suggestions. 


Thanks. 


- Bill 


Best Answer

Hi Bill,


right now we do not have MFA support in Royal TS and to be honest, it's kind of hard to implement it with Royal TS alone. We are currently planning some MFA related features with Royal Server, so that when you open a specific document from Royal Server, you have to provide a second factor. This is still in development and I can't really tell a release date for that yet.


Regards,

Stefan


Answer

Hi Bill,


right now we do not have MFA support in Royal TS and to be honest, it's kind of hard to implement it with Royal TS alone. We are currently planning some MFA related features with Royal Server, so that when you open a specific document from Royal Server, you have to provide a second factor. This is still in development and I can't really tell a release date for that yet.


Regards,

Stefan

Hello, how is MFA development for Royal Server coming along?

Hi Ian,

in Royal Server we do have MFA support for document access. Once you set it up, you need to provide a second factor to open the document:

https://royalapplications.com/server/main/features-new


Regards,

Stefan

Excellent, this is great! Thanks Stefan
Hi Stefan, I don't get prompted for MFA when I try to open documents. It just tells me that MFA is forced and to contact my administrator... ?

Hi Ian,


I kindly ask you to open a support ticket here and provide some details and screenshots how you set up MFA on your server:

https://www.royalapplications.com/go/support-ticket-new


Thanks!

Sefan

If anyone is interested, I put in a Feature Enhancement Request for Royal Server Secure Gateway to support MFA...

https://support.royalapps.com/support/discussions/topics/17000015736

My company uses DUO for MFA when logging into servers via RDP.. Does RoyalTS still not support this? Does it support any MFA?


Thanks

Hi Tom,


Royal TS is using the Microsoft RDP ActiveX component which ships with Windows. So we don't have much control over the behavior of the component. I know that customers have successfully implemented MFA and are using Royal TS but I'm not sure which vendor/product was involved. It's actually not up to Royal TS to support this, it's more up to the component if it can support the MFA implementation. I'm not really familiar with DUO's MFA with RDP but maybe they can clarify if this also works with the ActiveX component.


Regards,
Stefan

Thank you for the reply Stefan.. Just to elaborate on the experience.. When I use the standard mstsc and RDP to one of our servers, it logs into the server and then there is a DUO client running on the server that sends a push notification to our phone (which has the DUO app installed)..


We can see the Windows login screen and a DUO window when this happens and we just can't get into the server fully until we approve the push notification.. Once we do it logs in fully..


When I try to connect/RDP via RoyalTS it just bounces back saying the credentials did not work even though they are the correct ones.. 

Hi Tom,


thanks for the details. I'm not sure if this is a limitation of the ActiveX component or if a different setting (like NLA or authentication level) is causing the issues. Can you try Microsoft's RDCM (which uses the same component)?

https://docs.microsoft.com/en-us/sysinternals/downloads/rdcman


Yes, that actually works.. Also, Remote Desktop Manager - Remote Connection Management which appears very similar to RoyalTS also works..


Hopefully it's just a setting I need to modify in RoyalTS as I've been a user of your product for almost a decade and don't want to switch..


Thanks for the quick replies..

Stefan, yes I can use RDCM with DUO with no issues.. I can also use Remote Desktop Manager - Remote Connection Management which is very similar to your product (as far as GUI goes).. I'm a longtime user of RoyalTS so hoping it's just a setting I'm missing..


Thanks

That's good news. If RDCM works, Royal TS will too. I assume that one of the settings has a different default value in Royal TS which causes the issue. I guess it would be best to provide more data (settings, screenshots, videos) to further investigate. I recommend opening a support ticket for that as personal/sensitive information may be required:

https://www.royalapps.com/go/support-ticket-new

Login or Signup to post a comment