Configure Idaptive Identity Service for RADIUS

Idaptive Identity Service supports RADIUS in the following ways.

Support type Use case Description
Idaptive Connector as a RADIUS server Provide MFA for RADIUS clients, such as VPNs

Integrate Idaptive Identity Service with your RADIUS client to provide a second authentication layer for added security. For example, if a VPN concentrator uses RADIUS for authentication, you can configure email as a secondary authentication requirement. A typical work flow is when a RADIUS client (like a VPN server) uses the Idaptive Connector as a RADIUS server to authenticate an incoming user connection. Depending on the user type, the connector authenticates the credentials either through Active Directory or Idaptive Identity Service and returns the authentication result to the RADIUS client. This diagram shows the work flow.

Radius Client

See Configure the Idaptive Connector for use as a RADIUS server for general configuration steps, or reference one of the following topics for details on a specific RADIUS client:

Idaptive Connector as a RADIUS server

Provide only the second authentication factor for RADIUS clients

Keep your existing primary authentication (for example, Active Directory) and configure the Idaptive Connector as a RADIUS server to provide only the second authentication factor for RADIUS clients that support secondary authentication factors.

See Configure the Idaptive Connector for use as a RADIUS server for general configuration steps, or reference one of the following topics for details on a specific RADIUS client:

Idaptive Connector as a RADIUS client Provide MFA for Idaptive Identity Service using an external RADIUS server

When users attempt to log in to Idaptive Identity Service and selects an external RADIUS server as a multi-factor authentication (MFA) mechanism, we send the user credentials (username and passcode) to the connector, which validates them against the configured RADIUS server, and returns the result of that validation to Idaptive Identity Service. This diagram shows the work flow.

Radius server

See Configure the Idaptive Connector for use as a RADIUS client for configuration details.