Connect Your Cloud Access Service Deployment to Authentication Manager
a month ago

Connect Your Cloud Access Service Deployment to Authentication Manager

You can perform two types of integration with Authentication Manager.

Integration TypePerformed From
Connect the Cloud Access Service to AMCloud Administration Console
Connect AM to CASThe Security Console in AM. Requires Authentication Manager version 8.4 Patch 4 or later.

Note:  To enable the High Availability Tokencode feature, see Enable High Availability OTP in Cloud Access Service.

Connect the Cloud Access Service to AM

You can connect Cloud Access Service (CAS) to AM to allow users with SecurID tokens to access SaaS and on-premises web applications and RADIUS clients protected by CAS. For configuration instructions, see Enable SecurID Token Users to Access Resources Protected by the Cloud Access Service. Use the Platform > Authentication Manager page to test the connection.

Connect AM to CAS

After you connect AM to CAS, AM users can access agent-protected resources using the RSA Authenticator app on registered devices. You must select an access policy and generate the Registration Code. You will need the information generated on this page to configure the connection from the Security Console in AM version 8.4 Patch 4 or later.

Before you begin 

  • You must be a Super Admin for CAS.

  • Decide which access policy will be applied to all users who access these resources. The policy must contain at least one cloud authentication method that AM supports. If you decide to rename this policy or select a different policy at a later date, you must regenerate the Registration Code and perform the connection steps again in the Security Console. You can edit settings within the policy at any time without reconnecting.

Procedure 

  1. In the Cloud Administration Console, click Platform > Authentication Manager.

  2. Select a 1.0 Access Policy from the drop-down list.

  3. Click Generate Code to generate a code and a registration URL. This code is valid for 24 hours.

  4. (Optional) Select a Network Zone from the drop-down list to allow or block IPs for Authentication Manager's connection to CAS.For more information, see Manage Networks

After you finish 

Copy the Registration Code and Registration URL and return to the Security Console. Either continue deploying the embedded identity router as described in Quick Setup - Connect RSA Authentication Manager to the Cloud Access Service with an Embedded Identity Router or complete the wizard as described in Connect Authentication Manager to the Cloud Access Service.