aXsGUARD Identifier 3.0.2.0 Product Guide v1.5
User Authentication Process
Authentication Process
Image 15: Back-end Authentication Process with Microsoft Active Directory
There are two steps (see image above) to back-end authentication with Microsoft Active Directory :
1.
First the back-end server for authentication needs to be identified. A User ID can be provided for
authentication with or without inclusion of the domain reference (i.e. the
' part).
If the domain is included and exists, the back-end server for the domain is identified.
If the domain is not included, or is included but does not exist, and a default domain is specified in the policy
for the client, the back-end server for the default domain is identified.
If the domain is not included, or is included but does not exist, and a default domain is not specified in the
policy for the client, the back-end server for the Master domain is identified.
2.
Once the back-end server is identified, binding (i.e. back-end authentication), can be completed using the
User ID and password provided with the authentication request:
If the bind on the back-end server succeeds, the user authentication on the aXsGUARD Identifier is
successful.
If the bind on the back-end server fails, the authentication on the aXsGUARD Identifier fails.
©
2009 VASCO Data Security
48