With the increasing requirement of MFA for system logins we have upgrading customers and converting them to use LFDS rather than the web client default login. This brings up a question on the LFDS STS service.
On most of the normal internal only systems the LFDS and STS services are installed on the same machine. When a customer wants to access the system external, we have allowed the STS service or they cannot use LFDS to login. Most of the customer have a web/DMZ VLAN that they place the web servers and a server/internal VLAN that Laserfiche Server lives on with LFDS.
Can the LFDS STS service be installed on the web server by itself and only have the 5058/5059/443 ports open between the web server and the LFDS/Laserfiche server and function with no added time delay with logins?