ADFS MFA Firewall rules for outbound communication #345
-
Hi, we've tried to install this plugin on an isolated ADFS environment (servers are not allowed to communicate with the internet) and have experienced some issues:
After allowing outbound communication for this environment, the plugin works as expected. This raises the question of which endpoints the plugin utilizes. While crawling through the source code I've found the following URLs:
My followup questions are:
Thank you in advance! |
Beta Was this translation helpful? Give feedback.
Replies: 4 comments
-
Hi, The plugin can work without the ADFS servers having access to the internet. Regarding the URLs indicated:
regards |
Beta Was this translation helpful? Give feedback.
-
Beta Was this translation helpful? Give feedback.
-
ConstrainedMetadataRepository
and then |
Beta Was this translation helpful? Give feedback.
-
@redhook62 thank you! To sum it up: The best solution in such an environment is to create restricted outbound firewall rules to allow the blob file to be downloaded. |
Beta Was this translation helpful? Give feedback.
ConstrainedMetadataRepository
and deploy this file on your servers in \ProgramFiles\MFA\Config rename the downloaded file as blob.db
and then
restart-service mfanotifhub