Reading through the Laserfiche 10.4.2 release notes and it looks like MFA is only supported for Laserfiche User accounts in LFDS. Are there plans to expand this to Windows Accounts within LFDS as well without having to use AD FS?
Question
Question
MFA for Windows Accounts in LFDS?
Replies
If your Windows logon already required MFA wouldn't it be redundant to require MFA again to sign into Laserfiche with Windows Authentication?
A lot of setups do not require MFA to log into a Windows machine itself, but when logging into web applications it is common to require MFA.
It is not on the roadmap at this time.
While it is increasingly common to require MFA before accessing a web application, I haven't seen seen MFA within a web application used alongside Windows Authentication (rather than SAML or a proprietary login process for non-AD users).
Do you have specific examples or a lot of customers that are using this setup? If so, I'd be interested in learning more.
Rather than using AD FS, customers can change to SAML authentication for AD users; we've seen a strong increase in SAML adoptions since many web applications support SAML that do not support Integrated Windows Authentication and companies want to be consistent in their authentication experience.
To help customers transition from Windows Authentication to SAML Authentication, the latest release of LFDS supports enabling SAML authentication for existing Active Directory users through the Identity Provider configuration.