VIP (Validation ID Protection)

 View Only
  • 1.  Symantec VIP for specific Group_ OWA

    Posted Jan 22, 2020 05:04 PM


     

    We are trying to enable MFA for OWA (Outlook Web Access) for a specific group in Active directory as below :

     

    • Customer has 1000 users.
    • The customer has 300 licenses only.
    • We want to enable MFA for 300 users to be protected with MFA.
    • We want the remaining 700 users to login without MFA using AD credentials.


      how to achieve that?


  • 2.  RE: Symantec VIP for specific Group_ OWA

    Broadcom Employee
    Posted Jan 22, 2020 05:27 PM

    What OWA integration are you using? (ADFS, IIS, Oracle...)



  • 3.  RE: Symantec VIP for specific Group_ OWA
    Best Answer

    Posted Jan 23, 2020 02:53 AM

    Hi 

    You can achieve that in the user store , there is a filter to include or exclude some users, groups , OUs . 

    I recommend to create a group for all the users that you want to enable MFA and put it in that folder as shown in the below article 

    https://support.symantec.com/us/en/article.tech22654.html 

     

    Please let me know if it solves your problem , and Please mark it as a solution .



  • 4.  RE: Symantec VIP for specific Group_ OWA

    Posted Jan 23, 2020 08:25 AM

    Andreas Horlacher I'm using IIS



  • 5.  RE: Symantec VIP for specific Group_ OWA

    Posted Jan 23, 2020 08:27 AM

    Fady azab Hi Fady 

    what will happen for the excluded Users ?? will be bypassed the VIP and will be able to login using AD credentials?



  • 6.  RE: Symantec VIP for specific Group_ OWA

    Posted Jan 23, 2020 09:27 AM

    Yes exactly , they will just login with the AD credentials 



  • 7.  RE: Symantec VIP for specific Group_ OWA

    Broadcom Employee
    Posted Jan 23, 2020 09:34 AM

    Fady is correct. Using the filter and including/excluding users in a particular group is how to achieve this. 



  • 8.  RE: Symantec VIP for specific Group_ OWA

    Posted Jan 23, 2020 04:49 PM

    Thanks Fady and Andreas 



  • 9.  RE: Symantec VIP for specific Group_ OWA

    Posted Aug 14, 2020 12:13 PM
    eyad,

    Have you implemented this? Does it work?

    My understanding is that when enabling VIP for OWA, MFA is active for all login attempts.
    And as long as one is not a member of a defined AD group, access will be denied, irrelevant if one provides VIP credentials or not.

    Regards,
    Koen