Start a new topic
In Progress

MFA for Secure Gateway

=== Feature Enhancement Request ===

We're trying out the Multifactor Authentication (MFA, a.k.a, two-factor or 2FA) feature on the Document Store on Royal Server.  It works great!  But that's not quite what we needed.


Can we do MFA on the Royal Server Secure Gateway?  For instance, when the engineers arrive in the morning they would have to MFA to get their first connection through the Secure Gateway but after that, all new sessions would go through the Secure Gateway without re-checking the MFA.


There should probably be a setting for Maximum-Session-Time to time-out the session and force the MFA to repeat.  We'd probably set ours to 30 hours or something to let users get a full day's work in.  


We use Duo Security here but the Microsoft Authenticator is a valid second option for us.


Thank you.


11 people like this idea

Hi Serban,


I recommend you contact our support team with the license details of your current license to work out how to upgrade your license:

https://www.royalapps.com/go/support-ticket-new


Regards,
Stefan

we tested and is working fine. Clean and simple as we wish. Good job !

We used a trial license 30 days in order to test. 

How can we convert the version 4 permanent license in a version 5 permanent license ?

Thank you

Good news Stefan !

We will test the new version with MFA and provide feedback.

Regards

Hi Serban,


yes, we released our new major versions a couple of days ago. See: https://www.royalapps.com/go/kb-server-main-releasenotes


Regards,
Stefan

Hi Koell


any new on this ?

thank you

I can't really tell the exact date, sorry. All I can say is that we are currently working on finalizing everything for the release. I surely hope it will be before the end of August - probably/hopefully earlier.

Hi Koell,

as our Security Company push us to move away from Royal TS if not MFA implement, can you please indicate a deadline for the official release ? We need to indicate this info in order to have internal approval for a security exception. aka accept the risk for some time ....

Thank you


Still in beta but the release is just around the corner. Stay tuned...

The official version of Royal TS Gateway with MFA was released ?

Thank you


New UI looks very good! Hopefully we have a full release shortly! Our team is dying to get this but in-stable!

We have no specific date right now. We are currently reworking the Royal Server console UI and we are not really sure how long this will take but we aim for May, hopefully April.

Hey Stefan,

Any idea on when this will come out of beta and into the stable version?

okay, finally got this working today and first impressions are good.

A few suggestions

1) When adding the MFA users and the standard windows "Select Users or Groups" comes up, it would be good to default to Entire directory if the server is in a domain. An alternate would be to detect where in the tree the last search was performed from and repeat the use of that node unless changed. 

Adding a number of domain users gets old real quick when having to keep switching from the local server to the domain :(

2) I'd like the ability to add both the user_id and the cache timeout to the MFA userlist via the column chooser. In general I think you should have the option of seeing every value presented in the user that exists in the edit field for a user

All in all this is really promising and I'm looking forward to seeing where it ends up ! It helps enormously with the sell job to management both of Royal TS and RoyalServer

Hi Stephen,


you can find our beta versions here: https://www.royalapps.com/go/kb-all-downloadbeta


Docs are still a work in progress but can be found here: https://docs.royalapps.com/r2022/royalserver/management/multi-factor-authentication/index.html


Please make sure you test beta versions on non-production/non-critical machines and make backups of your files/settings before you proceed.


Regards,
Stefan

Is the beta implementing MFA available now ? If so what's the process for getting it ?

Login or Signup to post a comment