Looking for advise, MFA or additional step for access to a server over RDP

Reply
Highlighted
L2 Linker

Looking for advise, MFA or additional step for access to a server over RDP

I'm trying to add additional protection for users accessing resources on an isolated network. Is there any way that I can utilize our Palo Alto's to accomplish this scenario?

 

We do use global protect and user-id mapping already, but as an example I would like John while on his laptop\pc that whenever he access lets call it ServerA over RDP that he has to do some sort of additional step to gain access into that network\destination. Possibly use some sort of multi-factor authentication or something similar?

 

Any ideas?

 

 

Tags (2)
Highlighted
Cyber Elite

@zthiel,

Might want to look into Authentication profiles. That would allow you to do what you are looking for. 

Highlighted
L2 Linker

Do I need to have a 3rd party product like Duo, Okta, etc? Or can I just use our backend service\server to have the user authenitcate against? Granted I believe if I want to use MFA then I could incorporate Duo, Okta, etc, correct?

Highlighted
Cyber Elite

@zthiel,

If your looking for an additional Authentication outside of  GlobalProtect I'm not sure why you wouldn't use some sort of MFA for the auth profile if you are looking for an additional authentication attempt on that server. 

Highlighted
L2 Linker

I'm more so looking to "fort knox" style access to a backend resource the best I can utilizing the Palo Alto's. If it's a little difficult for this subset of end users I am ok with it. I just really want to ensure a user is who they are when they go to access the resource. I do have it working, however it seems to only work for http\https requests, if I initiate a RDP session to the same server the traffic never leaves the laptop. But if I successfully sign into captive portal first and then launch the RDP to the same server then I am able to connect via RDP.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!