CA Service Management

 View Only
Expand all | Collapse all

Service Management Multi Factor Authentication (MFA)

  • 1.  Service Management Multi Factor Authentication (MFA)

    Posted Aug 26, 2021 01:34 PM

    Hello, 

    We have a requirement in our organization to enable Multifactor Factor Authentication (MFA) for Service Desk Management and Service Catalog. 

    I found this document:

    Does CA SDM support two factor authentication (2FA)?

    I want to hear from the community if this has been implemented in your organizations and the details that can be shared. 

    Regards,

    Jose



  • 2.  RE: Service Management Multi Factor Authentication (MFA)

    Broadcom Employee
    Posted Aug 26, 2021 04:32 PM
    Service Desk maileater supports oauth 2.0  
    https://techdocs.broadcom.com/us/en/ca-enterprise-software/business-management/ca-service-management/17-3/Release-Information/CA-Service-Management-17_3_0_4-Release-Notes.html
    I am not aware of other MFA support


  • 3.  RE: Service Management Multi Factor Authentication (MFA)

    Posted Sep 01, 2021 02:58 AM
    Hello Jose.
    Just as an idea or a thought:
    I am thinking about the separation of authentication and authorisation, or better identity and service provider.
     
    I believe the following is possible.
    SDM can use SAML as an authentication mechanism and in this context acts as a service provider (sp).
    The authentication in a SAML context is done by an identity provider (idp).
    In my understanding: If you have a SAML idp which supports MFA, I assume , that with SAML, you could implement MFA for SDM.
    @Chi Chen: What do you think about this approach?

    Regards
    ....Michael​

    ------------------------------
    Regards
    ....Michael
    ------------------------------



  • 4.  RE: Service Management Multi Factor Authentication (MFA)

    Broadcom Employee
    Posted Sep 02, 2021 11:21 AM
    Certainly this is a good idea and possible.
    https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-additional-authentication-methods-for-ad-fs
    I can't find techdoc for this like we have for SAML https://techdocs.broadcom.com/us/en/ca-enterprise-software/business-management/ca-service-management/17-3/administering/administering-ca-service-desk-manager/enable-saml-authentication-for-ca-sdm.html


  • 5.  RE: Service Management Multi Factor Authentication (MFA)

    Posted Sep 03, 2021 08:49 AM
    Hello, 

    Thanks we are looking this approach. 

    We have a complex authentication environment where this migth work only for internal users. We also provide access to our main customer that it has it's own domains and Azure AD tenant (we currently connect EEM to their domains for authentication) and External users are manage in another domain.

    EEM help us out to connect to the multiple domains and aunthenticate everybody. 

    But certainly something to to look out. 

    Also, I was thinking that this MFA feature should be something to be considered as part of the product in future releases. MFA has become a requirement for finance industry for Internet Facing applications and I believe there should be other clients with the same situation.


  • 6.  RE: Service Management Multi Factor Authentication (MFA)

    Posted Sep 03, 2021 09:25 AM
    Hi Jose.
    I understand your requirement.
    My understanding of the overall concept: Authentication capability was always outside the product, except the pin authentication, which you don't want to use at all
    OS Authentication is supported since the beginning.
    EEM authentication is supported to integrate to external ldap based directories
    SAML support offers the most flexible way to integrate to whatever authentication capabilities customers are looking for.
    MFA is just one of them.
    Providing these authentication mechanism by the product itself, might be out of scope for several reasons.
    But this is just my personal point of view.
    ...Michael

    ------------------------------
    Regards
    ....Michael
    ------------------------------



  • 7.  RE: Service Management Multi Factor Authentication (MFA)

    Broadcom Employee
    Posted Sep 03, 2021 09:30 AM
    Indeed...authentication is almost always outside of product as you pointed out...OS/LDAP/EEM/SAML. With SAML, you can go further like MFA.


  • 8.  RE: Service Management Multi Factor Authentication (MFA)

    Posted Sep 03, 2021 10:25 AM
    I Understand.... but other products like ServiceNow, Freshworks, Manageengine, etc already hace the MFA as part of the product configuration. 

    Let's see how far we can get with SAML and our multiple domains escenario.


  • 9.  RE: Service Management Multi Factor Authentication (MFA)

    Posted Dec 08, 2021 08:26 AM
    Hi Jose, hi all,
    I think that you should vote for: Idea Details - Broadcom Community - Discussion Forums, Technical Docs, and Expert Blogs
    I found Idea today after customer asked me for it.

    Regards,
    Peter