Password Safe Authentication Types and Configuration

Authentication Types in Password Safe

The following authentication methods can be used with Password Safe:

  • Active Directory (AD): Create a Beyond Insight group and add AD users as members.

  • LDAP: Create a Beyond Insight group and add LDAP users as members.

  • Smartcard: Configure Password Safe to allow authentication using a smart card PIN.

  • RADIUS: Configure multi-factor authentication (MFA) with a RADIUS server.

  • Third-Party Authentication: Configure Password Safe to use authentication for web tools supporting SAML 2.0 standards (e.g., PingID, Okta, ADFS).

To add an Active Directory or LDAP directory service, navigate to Configuration > Directory Credentials in the Role Based Access area of the Beyond Insight Management Console.

Multi-Factor Authentication (MFA) with RADIUS and Duo

Password Safe can be configured to work with a RADIUS infrastructure for different providers, including Duo. This course focuses on configuring Duo as the RADIUS provider.

Duo Configurations

Beyond Insight and Password Safe support the following Duo configurations:

  • RADIUS Auto

  • RADIUS Challenge

  • RADIUS Duo Only

Configuration Steps

  1. Navigate to RADIUS Two-Factor Authentication within the console and click "Create RADIUS Alias".

  2. Apply the necessary information to configure the RADIUS server.

RADIUS Auto and RADIUS Challenge configurations using Duo
  • Create Radius alias.

  • Enter Duo for alias.

  • Enter the host.

  • PAP for the authentication mechanism and select forward username and password for initial request.

RADIUS Duo Only Configurations
  • Follow the same process as before, but choose "Forward username and token for initial request."

  • For the initial prompt, enter a message to be displayed on the Beyond Insight login page to guide users on the information entered.

After RADIUS MFA is configured, the login page for the end user will vary depending on the configured settings. In the example given, the login page is configured for Duo only authentication.

Time-Based One-Time Password (TOTP) as MFA

TOTP is an MFA form that can be used in Password Safe. Users can enable TOTP and register with an authenticator app (e.g., Google Authenticator, Microsoft Authenticator) to generate one-time codes.

Enabling TOTP

  1. Go to Configuration > Authentication Management > Authentication Options.

  2. Select the checkboxes to enable TOTP for new directory accounts and/or new local accounts.

Configuration options
  • SKU Intervals: Refers to how many one-time password tokens remain valid. The authenticator app generates a new token every 30 seconds.

    • The default value of 1 means that only tokens generated one interval in the past or future will be valid.

    • Increasing this value may be necessary if there's lag between the server and client.

    • One SKU interval = 30 seconds.
      1 SKU interval=30 seconds1 \text{ SKU interval} = 30 \text{ seconds}

Setting TOTP on User Accounts

  1. Go to Configuration > Role Based Access > User Management.

  2. Under the Users tab, select the ellipsis to the right of the user and then "Edit User Details."

  3. Scroll down to Authentication Options and select TOTP from the dropdown list.

  4. Click "Update User" to save your settings.

Enabling TOTP on a New User Account
  1. Go to Configuration > Role Based Access > User Management.

  2. Under the Users tab, select the "Create New User" option.

  3. Choose the type of user (local, Active Directory, etc.)

  4. Fill out the required information.

  5. Scroll down to Authentication Options and select TOTP from the dropdown list.

  6. Click "Create User" once finished.

User Device Registration

  1. When a user attempts to log in after TOTP is enabled, they will receive a prompt with a QR code to register their device.

  2. They can either scan the QR code with their device or manually input the alphanumeric code beneath it into the authenticator app.

  3. Once the code has been entered, the app will generate a six-digit authentication code.

  4. The user must enter that code into the authenticator code field and then click continue.

Logging in with TOTP

After device activation, each login requires entering a code from the authenticator app along with their username and password.

Unregistering a Device

  1. Go to the Users tab under User Management and select the ellipsis next to the name of the user.

  2. Select "Edit User Details" and scroll down to Authentication Options.

  3. Click the "Remove Device" text to unregister their device.

Viewing User Status

Click the "View User Details" option in the ellipsis to see whether a user has two-factor authentication enabled and if they have a device enrolled.

SAML Configuration with Microsoft Entra ID

Password Safe supports SAML as an authentication mechanism. This section demonstrates configuring SAML in Password Safe with Microsoft Entra ID as an identity provider.

Configuring SAML

  1. Create an enterprise application in Entra ID to host the SAML configuration for Beyond Insight.

    • Launch Entra ID, select "Add" and then "Enterprise Application."

    • Select "Create your own application."

    • Provide a name (e.g., Password Safe SAML) and select the option to integrate any other application you don't find in the gallery, non gallery.

  2. Log in to the Beyond Insight management console as an administrator and create a new SAML identity provider.

    • Navigate to Configuration > Authentication Management > SAML Configuration.

    • Select "Create New SAML Identity Provider."

  3. In Azure, select the "Setup Single Sign On" option for the newly created enterprise application and then select SAML.

  4. Click the edit button within Basic SAML Configuration.

    • Copy the entity ID from the SAML identity provider screen in Beyond Insight and paste it into the identifier field in Azure.

    • Copy the assertion consumer service URL from Beyond Insight and paste it into the Reply URL Assertion Consumer Service URL field in Azure.
      *Remember to save your settings in Azure once finished.

Adding a Group Claim in Azure

  1. Scroll down to the edit button next to attributes and claims.

  2. Add a group claim.

  3. Select security groups for the group that should be returned in the claim and keep everything else as the default settings.

  4. Save these options in Azure and return to Beyond Insight.

  5. In Beyond Insight, select Microsoft Entra ID as the user mapping option for your SAML identity provider.

Configure SAML Certificates

  1. In Azure, navigate to SAML certificates and select edit.

  2. Change the signing option to sign SAML response and assertion.

  3. Select SHA 256 for the signing algorithm, and then click save.

  4. Click the download link to download the Certificate Base 64.

  5. Return to Beyond Insight and your SAMHOL identity provider.

  6. Upload the certificate into the space provided.

  7. Under encryption and signing configuration, check the boxes to enable the want SAML response signed and want assertion signed options.

Copying Information from Azure to Beyond Insight

You will need the following:

  • Login URL

  • Microsoft Entra Identifier

  • Logout URL

Copy the Microsoft Entra Identifier into the identifier field in Beyond Insight, then copy the login URL into the single sign on service URL field, and the logout URL into the single logout service URL field.

On-Premises Installation URL Update

If using an on-premises installation (not Password Safe Cloud), update the host name and SAML access URL to remove the legacy version in the URL.

  • Navigate to Configuration > Authentication Management > Access URLs.

  • Modify the existing information to remove the ei.retina.cs.server text from the URL.

Granting Access to Users and Groups

  1. Select the enterprise application in Azure and go to assign users and groups.

  2. Click add user group, and then select all users and groups that you wish to grant access to.

Disabling Standard Login Form

Disable the standard Beyond Insight login form for users using SAML authentication.

  • For existing users: Configuration > Role Based Access > User Management > Edit User Details > Enable the "Disable Forms Login" checkbox.

  • For new accounts: Configuration > Authentication Management > Authentication Options > Enable the "Disable forms login for new directory accounts" checkbox.

Test SAML authentication by logging in as an existing user and selecting the "Use SAML authentication" option at the login screen.