Azure AD SSO and PH unlocking clarifications

Resolved

Azure AD SSO and PH unlocking clarifications

avatar

Hi there,

I need some clarifications about SSO login and unlocking features.

General SSO
We set up Azure AD SSO with success and synced groups too. We have one Devolutions standard account already in place with the same username (e-mail) of the Microsoft one; now, this user can log to Devolutions Portal and PH with his Microsoft credentials and Devolutions too: is it right? To avoid this, I think we need to use this PH setting:

forum image

But, what will happen for our admin Devolutions/PH accounts with no SSO logins? We will be cuttet off from our PH? If yes, how can we get access back?

Recovery 2nd factor method prompt?
What's the meaning of this prompt? Is it due to using password unlocking method instead of Workspace app?

forum image

Unlock step
We red KBs but we are not sure about this feature. Is "unlocking" related to PH instead of general Devolutions accounts? Why we need to unlock PH if the login is don through a SSO with MFA? Is unlocking bound to devices only for a specific account, so you only need to unlock new devices?

User auto-logoff
We really want that our PH users need to login back after few mins of inactivity, so we set up this setting in PH:
forum image
Our user (with both Devolutions and Microsoft account on the same username) is logging with Microsoft and after 5 mins is logged off; if he try to log back, he need to pass the Microsoft MFA again! As we understood by KBs, this is not correct as he should find his account cached inside the browser session (not closed) asking for Microsoft password only. Is it right? It's terribly tedious.

What's the meaning of "Block Tor traffic"? Is for blocking users to log to PH by the mean of a Tor connection?

Force prompt login
What's the meaning of "Force prompt login"? And how can be related to SSO?
forum image

Many thanks.

All Comments (7)

avatar

Again,

I tested a brand new Azure AD account as a member of our Azure AD group that is synced with Devolutions. After the Azure AD sync, the user appeared inside our Devolutions organization.

When this user try to login, the system ask him the security key method (as KB describes); if the user chose the "password method", then, he can login to Devolutions Portal with this credentials too (without MFA if not manually set up inside Devolutions Portal). After he is invited to PH, I suppose he could login with Devolutions credentials (instead of Azure AD), so without MFA. Is it right? If yes, not good at all and how to fix? I suppose with:

forum image

Thanks again.

avatar

With o without this option, my users can login with their Microsoft account anyway:

forum image

avatar

Hello,

We will check your different points and come back to you!

Best Regards,

Etienne Lord

avatar

Hope that you can help me understand because I'm actually unable to start our PH with all this doubts.

avatar

Hello,

We will be able to have a look at this during our call!

Best Regards,

Etienne Lord

avatar

Hello Nicola,

Thank you for your time yesterday! If you have any further questions, do not hesitate!

Best Regards,

Etienne Lord

avatar

Thank you too!