<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-6939520029032683172</atom:id><lastBuildDate>Sun, 07 Jun 2026 09:39:37 +0000</lastBuildDate><category>Active Directory</category><category>Windows</category><category>Windows 2008 R2</category><category>Microsoft</category><category>script</category><category>PowerShell</category><category>DPM</category><category>Migration</category><category>Exchange</category><category>Exchange 2010</category><category>AD</category><category>DPM 2010</category><category>DPM 2007</category><category>ForeFront</category><category>ADMT</category><category>Active Directory Migration</category><category>ADMT 3.2</category><category>Windows 7</category><category>Exchange 2007</category><category>Quest Migration Manager</category><category>QMM</category><category>PowerShell Profile</category><category>Hyper-V</category><category>Forefront Client Security</category><category>SharePoint</category><category>Windows Server 2008 R2</category><category>SCOM</category><category>SharePoint 2010</category><category>Virtual Server</category><category>Operations Manager</category><category>SID Filtering</category><category>TechNet</category><category>Management Pack</category><category>SID Filtering – Access is denied</category><category>ebook</category><category>Best Practices Analyzer</category><category>Outlook</category><category>SQL</category><category>Backup and Recovery Analysis</category><category>Exchange 2010 upgrade</category><category>SystemCenter</category><category>isa server</category><category>ADPREP</category><category>Azure</category><category>Backup Now Option</category><category>DPM hotfix</category><category>Forefront Client Security Installation and Issues</category><category>Office 2010</category><category>RMS</category><category>TMG 2010</category><category>TechNet Webcast</category><category>VHD</category><category>Webcast</category><category>Cloud Computing</category><category>DPM 2007 Version and Hotfix Information</category><category>DPM guide</category><category>DirectAccess</category><category>Domain</category><category>Group Policy</category><category>LDAP</category><category>MOSS</category><category>Office Communications Server</category><category>RDP</category><category>SQL 2008</category><category>Schema</category><category>Service Pack 2</category><category>TMG</category><category>Windows Mail</category><category>Windows Vista</category><category>capacity planning</category><category>exchange 2007 upgrade</category><category>exchange migration</category><category>santhosh sivarajan</category><category>upgrade</category><category>$profile</category><category>AD Snapshot</category><category>Active Directory limits</category><category>Beta</category><category>Blog</category><category>Configuration Manager vNext</category><category>DISM</category><category>DPM 2007 to DPM 2010 Upgrade</category><category>DPM 2010 RTM</category><category>DPM 2010 Release Candidate</category><category>Exchange 2007 Management Shell Quick Reference</category><category>Hyper-V Auto Protection</category><category>Internet Explorer</category><category>LDIFDE</category><category>Licensing</category><category>MIIS</category><category>Management Agent</category><category>NNTP Bridge</category><category>OCS</category><category>Rights Management Server</category><category>Rights Management Service</category><category>SCVMM 2008</category><category>SDK</category><category>SamAccountName</category><category>Silverlight</category><category>Sync</category><category>System Center</category><category>System Center Operations Manager</category><category>Training</category><category>Virtual Desktop Infrastructure</category><category>Vista</category><category>Windows Mail Vs Windows Mail Desktop</category><category>Windows XP Mode</category><category>blogcastrepository</category><category>dsamain</category><category>office 2007</category><category>$75FB00</category><category>APP-V</category><category>Active Directory Certificate Services Migration Guide</category><category>Alert Publishing</category><category>Apple iPod</category><category>Blogging in Word 2007</category><category>Book</category><category>Certification</category><category>Cloud Recovery</category><category>DPM 2007 and Tape Timeout</category><category>DPM Agent</category><category>DPM Beta to RTM Upgrade</category><category>DPM Service Pack</category><category>DPM Timeline</category><category>DPM V3</category><category>DPM download</category><category>Data Protection Manager</category><category>Domain Services was unable to initialize network connections for incoming LDAP requests</category><category>EMWProf</category><category>Forefront Online Protection for Exchange</category><category>GAL</category><category>HASMUG</category><category>Houston Area Systems Management User Group</category><category>IIFP</category><category>IPD</category><category>ISA Server 2004</category><category>LCS 2005</category><category>LDAP Authentication</category><category>Log on to</category><category>MAPI Editor</category><category>MFCMAPI</category><category>MOF</category><category>MSDTC - Confusing recommendations from Microsoft</category><category>Messenger for Mac</category><category>Microsoft Windows Server 2003 R2</category><category>NetIQ</category><category>Netmon</category><category>Operations Manager 2007 Release Candidate 2</category><category>Outlook Voice Access</category><category>Pre-Deployment Analyzer</category><category>Public Folder</category><category>SCOM Management Pack for Microsoft BizTalk Server</category><category>SQL Reporting Service</category><category>Simplifying Access Rules for ISA Firewall</category><category>SoftGrid</category><category>Startup and Shutdown Script</category><category>SyncToy</category><category>TechNet Webcast - Data Protection Manager 2010 - Rescheduled</category><category>Telnet</category><category>Things to Consider when Installing Exchange 2007</category><category>UAG</category><category>Uninstall McAfee and Install ForeFront Client Security</category><category>Uninstall Symantec and Install ForeFront Client Security</category><category>Update Rollup 1 for Exchange Server 2010</category><category>Virus</category><category>WIM</category><category>Widnows 2003 R2</category><category>Windows Live for Windows Phone</category><category>Windows Mobile 6 Demo</category><category>Windows PowerShell</category><category>connect.microsoft.com</category><category>email alert</category><category>ex</category><category>firewall</category><category>isa</category><category>ldifde.exe</category><category>msdtc</category><category>office 2010 e-book</category><category>sqlCrunch</category><category>www.sivarajan.com</category><category>0XC0000005</category><category>0x800423f4</category><category>0x80042515</category><category>0x80070490</category><category>0x80070643</category><category>1603 -Fatal error during installation</category><category>20% free tape threshold</category><category>2007 Microsoft Office Add-in: Microsoft Save as PDF</category><category>2155348253</category><category>3.0.7336.0</category><category>32 bit 64 bit</category><category>32538</category><category>71-663</category><category>ADCS</category><category>About</category><category>Active Directory Federation Services 2.0 RC</category><category>Active Directory Lightweight Directory Services</category><category>Advanced Group Policy Management</category><category>AllowLocalDataProtection</category><category>AltDefaultDomainName</category><category>An unexpected error occurred during job execution</category><category>Antigen</category><category>AppFabric</category><category>Attach Agent in DPM 2010</category><category>Automatic sign out from Live Communication Server</category><category>Available Memory 0 KB</category><category>Bare Metal Recovery of Windows Server 2008 Using DPM 2007</category><category>Bill Gates</category><category>Bitlocker</category><category>BizTalk Server</category><category>Bocada</category><category>CMS</category><category>CSVDE</category><category>CachePrimaryDomain</category><category>Cancellation Microsoft Beta 071-663</category><category>Cannot move the items</category><category>Cannot open the Outlook window</category><category>Cannot start Microsoft Office Outlook</category><category>Change Default Domain Name</category><category>Channel9</category><category>Check admin$ share using PoweShell</category><category>Chimney Offload</category><category>Cisco sues Apple over iPhone name</category><category>Client Computer Protection</category><category>Cmdlet</category><category>Confusing Acronyms</category><category>Copy Recovery Points to Tape</category><category>Copy-DPMTapeData</category><category>Create Recovery Point</category><category>Cross Platform Audit Collection Service Management Packs</category><category>Custom Provider Creation in MOM</category><category>Custom Tape Labels in DPM 2007</category><category>DAG</category><category>DEC 2007 Longhorn and MIIS Pre-Con Workshop</category><category>DFS</category><category>DLT-V4</category><category>DPM 2007 System State Backup</category><category>DPM 2007 System State Backup – Common Configuration Mistake</category><category>DPM 2010 PowerShell Script</category><category>DPM Agent – Common Installation Mistakes</category><category>DPM Alerts event log</category><category>DPM Centralized Management</category><category>DPM Database and SQL server Password</category><category>DPM Management Pack</category><category>DPM Management Shell</category><category>DPM TCO and ROI Calculator</category><category>DPM Webcast</category><category>DPM and Recovery Point Limit</category><category>DPM and SharePoint</category><category>DPM and Tape Size Limit</category><category>DPM and Tapes – Things to Consider</category><category>DPM could not connect to SQL Server Reporting Services</category><category>DPM install</category><category>DPMDB</category><category>DPMSetup has stopped working</category><category>DPMTemp</category><category>DPM_SYSTEM_STATE</category><category>Data Encryption Toolkit for Mobile PCs</category><category>Data Protection Manager 2007 – Tape Usage</category><category>Data Protection Manager 2010</category><category>Data Protection Manager 2010 Beta Download</category><category>DefaultDomainName</category><category>Dell</category><category>Dell TL 2000 and DPM 2007 Configuration</category><category>Delta Force Ranger Event</category><category>Deploying Windows 7Essential Guidance</category><category>Deployment Image Servicing Management</category><category>Desktop Search Engine</category><category>DisablePerformanceCounters</category><category>Djoin.exe</category><category>Do not forward</category><category>Dpmxxx.tmp</category><category>EFS</category><category>ESX</category><category>Edit ISO</category><category>Email Security</category><category>End of Tape reached</category><category>Error 0xe300000c - Cannot apply Mailbox Security Descriptor</category><category>Error 313</category><category>Error 360: The operation failed due to a virtual disk service error</category><category>Error ID:820</category><category>Event ID 6050</category><category>EventID: 546 Error</category><category>Exchange RTM</category><category>Exchange Recipient Policy Filter</category><category>Exchange Server 2007 Documentation</category><category>Exchange Server 2007 Setup Command Reference</category><category>Exchange Server 2010 Administrator’s Pocket Consultant</category><category>Exchange Server Intelligent Message Filter v2 Operations Guide</category><category>FCS Pre-requisite Failed</category><category>FeedSync</category><category>FeedSync - Synchronization for the Web</category><category>File Classification</category><category>File Replication Service</category><category>Firefrox</category><category>Five Hottest Jobs in Technology</category><category>Forces users to reactivate OS</category><category>Forest Recovery</category><category>GAL Sync</category><category>GAL for Smart Phones</category><category>GUID Partition Table</category><category>Geneva</category><category>Get control of your severs using Startup/Shutdown Script</category><category>Get-DPMLibrary</category><category>GodMode</category><category>Goove 2007</category><category>HP Sizer for Microsoft Hyper-V 2008 R2</category><category>HPC</category><category>HSPD-12</category><category>Handler Permissions</category><category>Happy Holidays</category><category>Happy Thanksgiving</category><category>ID 104</category><category>ID: 341</category><category>IE 7</category><category>IE Vs Firefox</category><category>IRM</category><category>IS</category><category>ISA Server Best Practices Analyzer Tool</category><category>ISA Server SDK</category><category>ISA VHD</category><category>ISO</category><category>IT Team Manager Live Meeting Series: Whatever happened to the MCSE?</category><category>Identify Domain Membership</category><category>Identify Physical Host of a Virtual Server using PowerShell</category><category>Import and Export Directory Objects</category><category>Information Store Viewer</category><category>Information Worker</category><category>Infrastructure Planning and Design</category><category>Inside the Windows Vista Kernel</category><category>Installing DPM 2010 on a Domain Controller</category><category>Internal error 0x809909FB</category><category>Internet Security and Acceleration Server 2006 VHD</category><category>Introduction to Blogging</category><category>Iron Mountain</category><category>Isolated Lab Using ISA Server</category><category>KB</category><category>KB976542</category><category>KMS</category><category>Key Management Service</category><category>Key Management Service  for Windows Server 2003 SP1 and Later</category><category>Large e-Mail Message Size</category><category>Lcsish.wsf</category><category>Learning Material</category><category>Library Name and Serial Number PowerShell Script</category><category>ListVApps</category><category>Local data protection on DPM Server</category><category>Lock-DPMLibraryDoor</category><category>Logical Access Authentication</category><category>Logon Error –2147221231</category><category>MAPI_E_LOGON_FAILED</category><category>MCITP</category><category>MCSE</category><category>MCTS</category><category>MS$DPM2007$</category><category>MSDN</category><category>MSDPMV3BETA1EVA</category><category>MVP</category><category>MagicISO</category><category>Malicious Software – MS White Papers</category><category>Management Shell</category><category>Metalogix</category><category>Microsoft Commerce Server</category><category>Microsoft Desktop Optimization Pack</category><category>Microsoft Exchange 2010 Beta</category><category>Microsoft Exchange Best Practices Analyzer Web Update Pack</category><category>Microsoft Forefront Client Security Product Documentation</category><category>Microsoft Forefront Server Security for SharePoint Management Pack</category><category>Microsoft Forefront Threat Management Gateway (TMG) Administrator&#39;s Companion</category><category>Microsoft Forefront Unified Access Gateway</category><category>Microsoft Forefront and System Center Demonstration Toolkit</category><category>Microsoft Global Contact Access for Windows Mobile Devices</category><category>Microsoft Office</category><category>Microsoft Office Accounting Express</category><category>Microsoft Office Communications Server 2007</category><category>Microsoft Office Groove 2007 demo</category><category>Microsoft Office Outlook Connector</category><category>Microsoft Office SharePoint Server 2007 VHD</category><category>Microsoft Outlook SMS Add-in (MOSA)</category><category>Microsoft Silverlight 4 Beta Documentation</category><category>Microsoft SoftGrid Demonstration Virtual Lab</category><category>Microsoft System Center Data Protection Manager 2007 is not supported on this operating system</category><category>Microsoft to make Vista available online</category><category>Migrating from Content Management Server 2002 to SharePoint Server 2007</category><category>Minimum Physical Memory Recommendation for Exchange 2007</category><category>Monitoring DPM Using SCOM 2007</category><category>Monitoring DPM using Microsoft Operations Manager</category><category>My First Peek into Microsoft Exchange 2010 By Santhosh Sivarajan</category><category>My New Year Resolution</category><category>NVSPBIND</category><category>Network access: Allow anonymous SID/Name translation</category><category>New Generation of Microsoft Certifications</category><category>NewSID</category><category>OMID</category><category>OWA Publishing Using ISA Server 2006 without RADIUS Server</category><category>Office 2007 and Exchange 2007 will be available on Nov. 30</category><category>Office 2007 is available on TechNet and MSDN</category><category>Office upgrade</category><category>Offline Domain Join Tool</category><category>One-Way GAL synchronization using IIFP</category><category>Open Vs Closed Book Exams</category><category>OpsMgr 2007 I/O Considerations</category><category>Outlook Express in Vista</category><category>Overrides In Operations Manager 2007</category><category>PAM</category><category>PFDAVAdmin</category><category>PKI</category><category>POP3</category><category>PSDatasourceConfig.xm</category><category>Port 5718 and 5719</category><category>Preparing for daylight saving time changes in 2007</category><category>Processor</category><category>Project Server</category><category>PromptingTimeOut</category><category>Protecting SAP using DPM 2007</category><category>Protecting Servers Using Selective Authentication</category><category>Protecting a Network from Unmanaged Clients</category><category>Protection tab</category><category>Publish Active Alerts</category><category>R3</category><category>RADIUS</category><category>RX</category><category>Recatalog an Expired Tape</category><category>Recover SharePoint</category><category>Remove DPM Agents</category><category>Remove Orphaned DPM Agent</category><category>Remove the record of the computer from this DPM server</category><category>Replica Creation is in Progress</category><category>Reply to All</category><category>Routing and Remote Access Service</category><category>Run/Emulate Windows Mobile 6 on your Computer</category><category>SEO</category><category>SQL 2008 Free E-Book</category><category>SQL Named Instance</category><category>SQL Password</category><category>SRS</category><category>Safely Remove Hardware</category><category>Search Engine Optimization Toolkit</category><category>Secondary DPM Server</category><category>Security Compliance Manager</category><category>Setup cannot query the system configuration</category><category>SharePoint 2010 Installation and Configuration</category><category>SharePoint 2010 – SQL Version Requirements</category><category>SharePoint Capacity Planning Tool</category><category>Sharepoint Workspace</category><category>Show all Recovery Points</category><category>Site Replication Service</category><category>Slow Performance</category><category>Society for Technical Communication Award</category><category>SoftGrid SMS Connector</category><category>Standard to Enterprise Upgrade</category><category>Storage Calculators for DPM 2010</category><category>Supportability Matrix</category><category>Sysprep</category><category>Sysprep cannot run on a computer</category><category>System Center Capacity Planner</category><category>System Center Operations Manager 2007 R2 Documentation</category><category>System Center Operations Manager 2007 RC 1</category><category>System Center Operations Manager 2007 is RTM</category><category>System Center Remote Operations Manager 2007</category><category>System Recovery Tool</category><category>System error 1214 has occurred</category><category>TAP Nomination</category><category>TCP Chimney Offload</category><category>TL 2000</category><category>TX</category><category>Tape Label</category><category>TapeSize</category><category>Team Foundation Server</category><category>Tech-Ed 2007 Online</category><category>TechNet Subscription</category><category>TechNet Virtual Labs</category><category>TechNet Webcast: How Microsoft IT Deployed Windows Vista</category><category>Teredo</category><category>The agent operation failed because the credentials you provided do not have sufficient user rights</category><category>UNIDEN WIN1200 Dual-Mode Cordless Internet Phone and Windows Live Messenger</category><category>URL Filtering</category><category>Unified Communications</category><category>Unknown error (0x80042515)</category><category>Unwilling to perform. The modification was not permitted for security reasons</category><category>VDI</category><category>VMware</category><category>VPC</category><category>VSS</category><category>VSSAdmin</category><category>Virus Scanning Recommendations For Window From Microsoft</category><category>Visio</category><category>Vista OEM BIOS Hacks</category><category>Vista and Offline File Issues</category><category>Vista bug</category><category>Vista slower than XP at start-up and shutdown</category><category>Vista was deleted from the MSDN and TechNet</category><category>Visual Studio</category><category>Volume Licensing</category><category>Volume Shadow Copy Service Operation Error</category><category>WORM tapes</category><category>What is Blogging</category><category>Windows 7 Application Compatibility List</category><category>Windows 7 ISO File</category><category>Windows 7 USB/DVD Download Tool</category><category>Windows Azure</category><category>Windows Desktop Search</category><category>Windows Installer Cleanup Utility</category><category>Windows Media Player 11 for Windows XP</category><category>Windows Restore to a Different Hardware</category><category>Windows Server 2008 Books</category><category>Windows Server 2008 Exam Details</category><category>Windows Server 2012</category><category>Windows Server 2016</category><category>Windows XP Mode and Screen Resolution</category><category>Word</category><category>XML Notepad 2007</category><category>You don&#39;t have appropriate permission to perfrom this operation</category><category>You have been sing out of SIP</category><category>\\.\BackOfficeStorage \</category><category>attach Agent</category><category>cable configuration</category><category>cap</category><category>cdoex.dll used by another application</category><category>cluster</category><category>detailed inventory</category><category>erase tape</category><category>event ID 1042</category><category>fast inventory</category><category>fo</category><category>generate a list of Exchange IM Users</category><category>get-itemproperty</category><category>groove</category><category>how much does an email cost</category><category>http://santhoshsivarajan.blogspot.com</category><category>iOS</category><category>iSCSI</category><category>install DPM 2010</category><category>loopback cable</category><category>mark tape as free</category><category>maximum number</category><category>netdom</category><category>new features</category><category>ocssetup</category><category>op</category><category>oper</category><category>pre-W2k</category><category>re-ACL</category><category>resetnavpane</category><category>vb script</category><category>wi</category><category>www.blogcastrepository.com</category><title>Santhosh Sivarajan&#39;s Blog</title><description>Microsoft Technology Blogs</description><link>http://santhoshsivarajan.blogspot.com/</link><managingEditor>noreply@blogger.com (Blog-5)</managingEditor><generator>Blogger</generator><openSearch:totalResults>627</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-7728408993857365158</guid><pubDate>Fri, 30 Mar 2018 07:00:00 +0000</pubDate><atom:updated>2018-03-30T09:55:20.841-05:00</atom:updated><title>PoweShell TTUC (Tips, Tricks and Useful Commands) #114 – Move Files and Folders</title><description>PowerShell TTUC (Tips, Tricks and Useful Commands) - #114&lt;br /&gt;
&lt;br /&gt;
Create a folder and assign appreciate permission using PowerShell&lt;br /&gt;
&lt;br /&gt;
$OutputLocation = &quot;C:\Temp\Folder1&quot;&lt;br /&gt;
$adminUser = &quot;Domain\Admin1&quot;&lt;br /&gt;
&lt;br /&gt;
#&lt;br /&gt;
if (-not(test-path $OutputLocaiton))&amp;nbsp; #verify the existance of &quot;C:\Temp\Folder1&quot; fodler&lt;br /&gt;
{&lt;br /&gt;
&amp;nbsp; &amp;nbsp; #if not create a new folder&lt;br /&gt;
&amp;nbsp; &amp;nbsp; New-Item -ItemType directory -Path $OutputLocaiton | out-null&lt;br /&gt;
&amp;nbsp; &amp;nbsp; $cACL = Get-Acl $OutputLocaiton&lt;br /&gt;
&amp;nbsp; &amp;nbsp; $nACL = New-Object&amp;nbsp; system.security.accesscontrol.filesystemaccessrule($adminUser,&quot;Fullcontrol&quot;,&quot;Allow&quot;)&lt;br /&gt;
&amp;nbsp; &amp;nbsp; $cACL.SetAccessRule($nACL)&lt;br /&gt;
&amp;nbsp; &amp;nbsp; Set-Acl $OutputLocaiton $cACL&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
Reference -&amp;nbsp;&amp;nbsp;&lt;a href=&quot;https://blogs.technet.microsoft.com/josebda/2010/11/12/how-to-handle-ntfs-folder-permissions-security-descriptors-and-acls-in-powershell/&quot;&gt;How to Handle NTFS Folder Permissions, Security Descriptors and ACLs in PowerShel&lt;/a&gt;l&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2018/03/poweshell-ttuc-tips-tricks-and-useful.html</link><author>noreply@blogger.com (Blog-5)</author><thr:total>67</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1011716252165340146</guid><pubDate>Mon, 26 Mar 2018 07:00:00 +0000</pubDate><atom:updated>2018-03-26T02:00:10.641-05:00</atom:updated><title>Update Group Membership – PowerShell Script</title><description>&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
If you have multiple domains or performing a user or group migration,
you may need to manually update (depend on your scenario) the source or target group
membership.&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp; &lt;/span&gt;This script can be used to update
group membership based on source user’s group membership.&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp; &lt;/span&gt;The input for this script the user name (sAMAccountName)
and it assumes that the source and target sAMAccountName are the same.&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b style=&quot;mso-bidi-font-weight: normal;&quot;&gt;Input file (Users.csv)
Format:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;b style=&quot;mso-bidi-font-weight: normal;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKbVbQhEvyysHlTB96QskGw6vYofuzj6xH9GmsbqLa2QAeLr6wKsUDnhijS_9-0dQ0HdGvIl3axamym06GPp3nkGvZyYkFZ7WBV5pryPH7l0vFbAUeHixttBRg8vkgA5H1FQM4vA9J6Nw/s1600/InputFile.PNG&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;298&quot; data-original-width=&quot;490&quot; height=&quot;194&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKbVbQhEvyysHlTB96QskGw6vYofuzj6xH9GmsbqLa2QAeLr6wKsUDnhijS_9-0dQ0HdGvIl3axamym06GPp3nkGvZyYkFZ7WBV5pryPH7l0vFbAUeHixttBRg8vkgA5H1FQM4vA9J6Nw/s320/InputFile.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/b&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Script validates users in the source domain and collect “memberof”
details and then add the target user (migrated user) to the same group. At the
end of the operation, the source user and the target user (migrated user) will
be part of same security group in the source domain.&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
You can see some other “Update Group Membership” script here
- &lt;a href=&quot;http://portal.sivarajan.com/2014/01/update-group-membershippowershell-script.html&quot;&gt;http://portal.sivarajan.com/2014/01/update-group-membershippowershell-script.html&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b style=&quot;mso-bidi-font-weight: normal;&quot;&gt;Script:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
# Update Group Membership&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
# Santhosh Sivarajan (Santhosh@Sivarajan.Com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Clear&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Import-Module ActiveDirectory&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$userN = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$GroupDetails = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$Group = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$GroupsDN = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$uValidation = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$tagetDomain = &quot;labanddemo.com&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$Cdate = (Get-Date).tostring(&quot;dd-MM-yyyy-hh-mm-ss&quot;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$SGBeforeUpdateFile =
New-Item -type file -force &quot;C:\Temp\Groups_Before_$Cdate.csv&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$SGAfterUpdateFile =
New-Item -type file -force &quot;C:\Temp\Groups_After_$Cdate.csv&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Import-CSV
&quot;C:\Temp\Users.csv&quot; | % { &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$userN = $_.userName&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$sourceDomain = $_.Domain&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$uValidation =
Get-ADUser -filter {sAMAccountName -eq $userN} -Server $tagetDomain&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;If($uValidation -eq $Null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;Write-Host &quot;User $userN Doesn&#39;t Exist in $tagetDomain Domain&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$errorFile = New-Item -type file -force
&quot;C:\Temp\Error_$Cdate.csv&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&quot;User $userN Doesn&#39;t Exist in $tagetDomain Domain&quot;| Out-File
$errorFile -encoding ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Else&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$userN
| Out-File $SGBeforeUpdateFile -encoding ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$GroupDetails = get-aduser -Server $sourceDomain -identity $userN
-Properties memberof&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;$GroupsDN =
$GroupDetails.memberof&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$GroupsDN | Out-File $SGBeforeUpdateFile -encoding ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;foreach ($Group in $GroupsDN)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;$MigrateduserN = Get-ADUser $userN
-Server $tagetDomain -Properties DistinguishedName&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;Write-host &quot;Adding User -&amp;gt; $MigrateduserN&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;Write-host &quot;To Group -&amp;gt; $Group&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Add-ADGroupmember -Server $sourceDomain
-Identity $Group -Members $MigrateduserN&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$members = Get-ADGroupmember -Server $sourceDomain -Identity $Group&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$GroupName = Get-ADGroup -Server $sourceDomain $Group&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$GroupName.Name | Out-File $SGAfterUpdateFile -encoding ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;$members.distinguishedName | Out-File $SGAfterUpdateFile -encoding ASCII
-append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/span&gt;Write-host &quot;....Done!&quot;
-ForegroundColor Green&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;Write-host &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b style=&quot;mso-bidi-font-weight: normal;&quot;&gt;Download:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
You can also download the script from the following locations:&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://1drv.ms/f/s!AicxxOGWxk8AekOoqTa9tZcySbQ&quot;&gt;OneDrive&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;TechNet Gallery&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2018/03/update-group-membership-powershell.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKbVbQhEvyysHlTB96QskGw6vYofuzj6xH9GmsbqLa2QAeLr6wKsUDnhijS_9-0dQ0HdGvIl3axamym06GPp3nkGvZyYkFZ7WBV5pryPH7l0vFbAUeHixttBRg8vkgA5H1FQM4vA9J6Nw/s72-c/InputFile.PNG" height="72" width="72"/><thr:total>38</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1573650691885415005</guid><pubDate>Fri, 23 Mar 2018 07:00:00 +0000</pubDate><atom:updated>2018-03-23T02:00:23.755-05:00</atom:updated><title>Group Membership Report – PowerShell Script</title><description>Another “Group Membership Report” script.&amp;nbsp; You can see some of the previous versions
here - &lt;a href=&quot;http://portal.sivarajan.com/2010/08/list-group-members-in-active.html&quot;&gt;http://portal.sivarajan.com/2010/08/list-group-members-in-active.html&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
This script provides the group membership details based on
user name.&amp;nbsp; You can include all user
names in an input file (Users.csv) in the following format:&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOKATxWu-D9Bvd_87DKJRK7IFxr4h6ENSsyfMprfX3jQqNjohIHB0ypVKkewcMz3ij9IiuLCSkKk_d5b7dsGK-J-QGXwYDgNeCDvnCyxiq0-TuVsq-sU9bdBqpa-rmhcm4sDU3w4rZb_8/s1600/InputFile.PNG&quot; imageanchor=&quot;1&quot; style=&quot;clear: left; float: left; margin-bottom: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;298&quot; data-original-width=&quot;490&quot; height=&quot;194&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOKATxWu-D9Bvd_87DKJRK7IFxr4h6ENSsyfMprfX3jQqNjohIHB0ypVKkewcMz3ij9IiuLCSkKk_d5b7dsGK-J-QGXwYDgNeCDvnCyxiq0-TuVsq-sU9bdBqpa-rmhcm4sDU3w4rZb_8/s320/InputFile.PNG&quot; width=&quot;320&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
Script uses &lt;a href=&quot;https://docs.microsoft.com/en-us/powershell/module/activedirectory/get-aduser?view=winserver2012-ps&quot;&gt;Get-ADUser&lt;/a&gt;
cmdlet to validate the user first then get the user membership using the “memberof”
properties.&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp; &lt;/span&gt;Output/report will be in the
GMReport_$Cdate.csv file.&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp; &lt;/span&gt;Error message
will be captured in Error_$Cdate.csv file. &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b style=&quot;mso-bidi-font-weight: normal;&quot;&gt;Script:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#Group Membership Report – PowerShell Script&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#Santhosh Sivarajan (santhosh@sivarajan.com)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
#&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Clear&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
Import-Module ActiveDirectory&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$userN = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$GroupDetails = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$Group = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$GroupsDN = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$uValidation = &quot;&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
$Cdate = (Get-Date).tostring(&quot;dd-MM-yyyy-hh-mm-ss&quot;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$Report = New-Item -type file
-force &quot;C:\Temp\GMReport_$Cdate.csv&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Import-CSV
&quot;C:\Temp\Users.csv&quot; | % { &lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$userN = $_.userName&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$sourceDomain = $_.Domain&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$uValidation = Get-ADUser
-filter {sAMAccountName -eq $userN} -Server $sourceDomain&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;If($uValidation -eq
$Null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Write-Host
&quot;User $userN Doesn&#39;t Exist in $sourceDomain Domain&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$errorFile =
New-Item -type file -force &quot;C:\Temp\Error_$Cdate.csv&quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&quot;User $userN
Doesn&#39;t Exist in $sourceDomain Domain&quot;| Out-File $errorFile -encoding
ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Else&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$userN | Out-File
$SGBeforeUpdateFile -encoding ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$GroupDetails =
get-aduser -Server $sourceDomain -identity $userN -Properties memberof&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$GroupsDN =
$GroupDetails.memberof&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;$GroupsDN |
Out-File $SGBeforeUpdateFile -encoding ASCII -append&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot; style=&quot;line-height: normal; margin-bottom: .0001pt; margin-bottom: 0in;&quot;&gt;
&lt;span style=&quot;mso-spacerun: yes;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
&lt;b style=&quot;mso-bidi-font-weight: normal;&quot;&gt;Download:&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div class=&quot;MsoNormal&quot;&gt;
You can also download the script from the following locations:&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;https://1drv.ms/t/s!AicxxOGWxk8AgpRVA8TbigFWfcGmsg&quot;&gt;OneDrive&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;TechNet Gallery&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
&lt;br /&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2018/03/group-membership-report-powershell.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOKATxWu-D9Bvd_87DKJRK7IFxr4h6ENSsyfMprfX3jQqNjohIHB0ypVKkewcMz3ij9IiuLCSkKk_d5b7dsGK-J-QGXwYDgNeCDvnCyxiq0-TuVsq-sU9bdBqpa-rmhcm4sDU3w4rZb_8/s72-c/InputFile.PNG" height="72" width="72"/><thr:total>151</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-6244477067253082418</guid><pubDate>Fri, 22 Dec 2017 08:00:00 +0000</pubDate><atom:updated>2018-03-30T09:40:52.320-05:00</atom:updated><title>Advanced Threat Analytics–Attack Simulation and Demo – Part1</title><description>&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/advanced-threat-analyticsattack.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part1&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part2&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part3&lt;/strong&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Microsoft Advanced Threat Analytics (ATA) is an user and entity behavior analytics solution to identify and protect protect organizations from advanced targeted attacks (APTs).&amp;nbsp; You can read more information about Microsoft Advanced Threat Analytics (ATA)&amp;nbsp;&lt;a href=&quot;https://www.microsoft.com/en-us/cloud-platform/advanced-threat-analytics&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;.&amp;nbsp; The purpose of this blog is to provide a few methods which can be used to simulate and demonstrate some of the basic attacks for demo and testing purpose.&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Suspicious Activity Simulation #1&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;strong&gt;ATA Gateway Stopped Communicating&lt;/strong&gt;&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
We will start with the most obvious one! – ATA communication issue.&amp;nbsp;&amp;nbsp; In this scenario, I am using&amp;nbsp;&lt;a href=&quot;https://docs.microsoft.com/en-us/advanced-threat-analytics/plan-design/ata-architecture#ata-gateway-and-ata-lightweight-gateway&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;ATA Light Weight Gateway&lt;/a&gt;(LWGW).&amp;nbsp; In this case Microsoft Advanced Threat Analytics Gateway (ATAGateway) service should be running on Domain Controllers.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To simulate this scenario,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Identify all Domain Controllers from the forest/domain. You can use the following&amp;nbsp;&lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;DSQUERY&lt;/a&gt;&amp;nbsp;command to get all DCs from the domain.&amp;nbsp;&amp;nbsp;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
DsQuery Server -Forest&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Stop the&amp;nbsp;&lt;strong&gt;ATAGateway&amp;nbsp;&lt;/strong&gt;service remotely&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Here are a few scripts -&amp;nbsp; S&lt;a href=&quot;http://portal.sivarajan.com/2010/07/stopstart-or-enabledisable-service.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;cript&lt;/a&gt;1 or&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2011/05/stop-start-disable-service.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Script2&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/p/scripts.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Script3&lt;/a&gt;&amp;nbsp;– if you want to go a script based approach&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Or we can use a simple SC command –&amp;nbsp;&lt;strong&gt;SC \\Lab-DC01 stop ATAGateway&lt;/strong&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIM3cSZEKIS5-0xHbJW86Vqof6h75E6M8h8i9NRZlxbCHwytmaiHdoCidxCXngFg34I4Qg7h7hFLZ3x0LBu2mOS_VXB1rz75eWq1q5PxvPHtof-nWty-KZFxhn-AwZW6lUKpdJqLjKUlI/s1600-h/image%25255B29%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;135&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_EaRvAb5Srxhsi3GFFDf-ncaJcJ63DfKYg2narkbaXXtrUa59PpSsfJiTkskqurn_ZVIcHnybJYJvsdTlpDosAWGhdywEtbPLaqiWCmEKwlhyHcz6xG9m9LbISIxzcEH5OF0N-t5Qc2s/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;625&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
You will receive the following high alert –&amp;nbsp;&lt;strong&gt;ATA Gateway Stopped Communicating&lt;/strong&gt;&amp;nbsp;– in Health Center.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsuEb4LNdMTqUsiyCOmoHnpvr3Ue5aaXuYUmc0cCj_-YnJA5x0P8pIP2IQFJ7Ebhr0TzMRu1w7wFXU69SMw1uGh2F-i0CM6ujHOTW_xJnctgpeYqHOwWJ6qR9RxU1riy-_QRRnBCPqZUk/s1600-h/image%25255B33%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;376&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVMDtR-V6ZmKx_AkXwwG2hwqGVfFx8IfZbpqai2mhyphenhyphengZzmqway1Iy80dG5vWPQhkupgwgndnVw2gZRFlVTDQ8roVImztX5NMN7BHyW77CCXoFcml9IwYFzKyaTI06fWIZmOzNUwpeAbYg/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;1064&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Suspicious Activity Simulation #2&lt;/strong&gt;-&amp;nbsp;&lt;strong&gt;Honey Token Account Activities&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
In general, the Honey Token accounts are non-interactive accounts.&amp;nbsp; These accounts can be dummy accounts for detect malicious activities.&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To simulate this scenario,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Create two 2 user accounts in Active Directory (ATA-Test1 and ATA-Test2)&lt;/li&gt;
&lt;li&gt;Add ATA-Test2 to Domain Admins group&lt;/li&gt;
&lt;li&gt;Get the SID of ATA-Test1 and ATA-Test2 using PowerShell or DSQUERY command&lt;ul&gt;
&lt;li&gt;dsquery * -filter (samaccountname=ata-test1) -attr objectsid (&lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Reference&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Get-ADUser Ata-test1 -Properties objectSID (&lt;a href=&quot;http://portal.sivarajan.com/search?q=script&amp;amp;x=0&amp;amp;y=0&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Reference&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Add this SID as Honey token accounts (&lt;strong&gt;ATA Console –&amp;gt; Configuration –&amp;gt; Detection –&amp;gt; Honeytoken Account SIDs&lt;/strong&gt;).&amp;nbsp;&lt;strong&gt;Save&lt;/strong&gt;&amp;nbsp;the configuration.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzRgv_vegLWLnDj5tH4XMmEShE4OjgjVks-9TNYmS94_lOT5GdXgo7_T9nsMHqFzDHrAGDer_JYR1CaO4fqKWUwAmy9H2Up4KgRBGbvWuihTvqObDAGPI4NScY_AYN8rhLt16iFhAz52E/s1600-h/image%25255B15%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;528&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3nxpxIaLyKC-xtZOjir-hK6xY0his2OF-4lhwYaw88P68gnBxoObwIto7OyJ8lTkgdjepBa_CBeA0ifp4HyV0SEcrT_7kPNTyWoOR3zeUH4_2SVB-b9X8Nt3VnfQAVcHFKwNQVx45h28/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;893&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Establish an integrative logon session using these accounts. You can RDP into a machine use these accounts&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;em&gt;&lt;strong&gt;Honey Token accounts (non-sensitive)&lt;/strong&gt;&lt;/em&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
You will receive the following alert/email with recommended actions in the ATA console.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOtVFpsuJyQUs_hiYTaItiBl8poRdEV1mVy2bdckKD-MknTb3-jzrwNKnoqyqn0PAmJpWXXu0UO30-KWpB-Bil-d39TVaV9zKNdqvwYaz9CeaFYgk9Idbvj_Y6SFmHk8KeqQ-dvfG7-Jg/s1600-h/image%25255B3%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;529&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_mTsi1qNe98YWt3TIeE29zZCZVPfa9XkJI72EvpYoaI0gjH-hX1wzUCBnMvc79LWWeRgu9eomLN7dwpWdm922BWueO5dIeu35GVgd4WMzRibLwZuL2oi_mTbdTVhLvmsEzPLnc9vOhm4/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;854&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;em&gt;&lt;strong&gt;Honey Token accounts (Sensitive)&lt;/strong&gt;&lt;/em&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Since ATA-Test2 account is a domain admin account, you will receive the same alert with &quot;&lt;strong&gt;Sensitive (S )&quot;&lt;/strong&gt;&amp;nbsp;indicating that this account is a high privileged account in Active Directory.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn8DNyu0z_KdoPvx21MnBotBgqRIoZxY-y9nIwdF1J6El1csbn7j7AEqTVPBEeNtBRjbAfHIfudxN5WX6QHKDwzyQoI91XV9v8gZX7MYNfVFq7m5uAeCm41Z2_tDHVddihTUPTDf1TUn8/s1600-h/image%25255B7%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;570&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMxxQLSgxyjwpiYfEmwetXuFVdqt3cFQaLKBLFD3QeZtn7Iwn3SnoUjLebMg4DWlVrXD0fowoZQzhCJfuJqP23IS-I2RgM8ToCO-YYB5uAFnO-aubyGrd2KMJ9NnclYIhHMdO3NZAVC-w/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;902&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;strong&gt;Suspicious Activity Simulation&amp;nbsp;&lt;/strong&gt;#3&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;– Massive Object Deletion&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Bulk object deletion can be a suspicious activity in an Active Directory environment.&amp;nbsp; ATA can alert alert you based on massive object deletion activities.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To simulate this scenario,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Create a few users in Active directory. Here is a sample PowerShell&amp;nbsp; script which you can use to create test accounts in Active Directory&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
Clear&lt;br /&gt;Import-module activedirectory&lt;br /&gt;$pass = ConvertTo-SecureString &quot;MyPassword0!&quot; –asplaintext –force&lt;br /&gt;for ($i=0;$i -lt 100;$i++)&lt;br /&gt;{&lt;br /&gt;$accountname = &quot;Test-Account$i&quot;&lt;br /&gt;Write-Host &quot;Creating $accountname&quot; -NoNewline&lt;br /&gt;New-ADUser –SamAccountName $accountname –name $accountname -OtherAttributes @{&#39;description&#39;=&quot;ATA Test User Account&quot;} -Path &quot;OU=Test Accounts,OU=User Accounts,DC=labanddemo,DC=com&quot;&lt;br /&gt;Set-ADAccountPassword –identity $accountname –NewPassword $pass&lt;br /&gt;Write-Host &quot;...Done&quot;&lt;br /&gt;}&lt;/blockquote&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Make sure ATA is &quot;learned&quot; about these account.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrUUJWYryiMO2R9AiuRtkihH4TEdYvLkog22ywQ_Sh0Dzg9_lrWLns6QgqmGFJMN_QfwtoAx8WyfeHJc8TRxsIJrQsHByCA4G-yY2znJAC54AfASAk2enF_NKux92BkoM6JB1eZu3isZY/s1600-h/image%25255B25%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;96&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMrJKxbwE9r80HZ7BDG3B3gjacl648bhNQQHATWkvhwC-uyIGrYkLDu3S7iJFnEoXB4-mxSMtb-cjgCJdTqQQsTCenhmByhkYEBTTr4c-2dCsgpba4u7ArCiJZ7266mV21vTe7gPYFhJ8/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;195&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Delete these accounts from Active Directory&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
You will receive the Massive Object Deletion alert in the ATA console right away as shown below.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj749uxMIZ_Lf7xDKPR2pOfj9Fih-el6s3Nx1G3eYGVjCMRjxRNopDvMpsou6SFd3ri6myHGQMy4DXov6rQuLkFZm_B8b2dGD0RYrSNw_VozoFtwfnGotThNCxMcccgSPoAILkvfkSo2fQ/s1600-h/image%25255B19%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;577&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCAAcDtwz5CRvySc2fVZEhpYkIeTDF9-DxZCfjzf_DDLhsL46vyqhX8QQ3vQCY6FqqamXBX7kExLeibdpMC50o2iTT3laztpvemcYY1H6vDezttLa0Za9UyrOOlwGem4mzJCBFtVANYAw/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;1072&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;strong&gt;Suspicious Activity Simulation&lt;/strong&gt;&amp;nbsp;#4 -&amp;nbsp;&lt;/strong&gt;&lt;strong&gt;Reconnaissance using DNS&lt;/strong&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
The DNS or name resolution information in a network would be&amp;nbsp; useful reconnaissance information. In general, DNS data contains a list of all the servers and workstations and the mapping to their IP addresses. Verifying this&amp;nbsp; information may provide attackers with a detailed view of the environment allowing attackers to focus their efforts on the relevant entities.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
For this simulation, the plan is to perform a DNS zone lookup using NSLOOKUP LS command.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To simulate this scenario,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Logon to a remote server.&amp;nbsp;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Open Command Prompt and run&amp;nbsp;&lt;a href=&quot;https://technet.microsoft.com/en-us/library/cc725991(v=ws.11).aspx&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;NSLOOKUP&lt;/a&gt;&amp;nbsp;command&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
From the NSLOOKUP window, run LS command to list the DNS zone&lt;/div&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunTCFmscQy-Lg07o5vUkavQYVtdrrD6IY8ZyV6NWKrzTI9uZtwYyjeO-qT4n2LRc6c7vMf1RhufQl_qzC5vNBz3RmxTG-7PkqLAZOkk0RGervqHsdcvXCSpiW74suYekqV1gAvFJmW_w/s1600-h/image%25255B41%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;113&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1270oc7TQKS9_AzsK6GTpOnlTLU6aqZ1xppRUTlU8LAtrmEnrgfS8zEUxq6yxY-L_8X7cST1YE3hIyzQlmJz88wstPl7BE1YCv9sE1rE3uOUChbEM7YehRyf3EVUhv3wVjs6MMhsPdkU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;668&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
You will receive the following&amp;nbsp;&lt;strong&gt;Reconnaissance using DNS&lt;/strong&gt;&amp;nbsp;alert the ATA console.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNwZR37ZCpUadSBiGAQIn-EWYu5bmpRzSjUeA5dxq1FTEBRVHvEtS-ZMFSmQAQI8Va1oZQ2yb3CmKdxoJt5yR8YtUoYXJu32qSm4XJ3gl8jSAgogyo9LnPRBypIkc58wZox39T9UOKR7A/s1600-h/image%25255B37%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;557&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpdtNVJVkuSFhMwPmOR6QF3VjZPdwNA_KFSq8A-W_So-Q79Xvi0FGr4fSei2S1k1nORV4UnbpZYCfpMU-bE8kQpJAx9FdavU1J_AiMOfBi3m47N-Iucf_ogQWViymQt3iZNIOw68_mHeM/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;860&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/advanced-threat-analyticsattack.html&quot; style=&quot;color: #1c5ea6; outline: none; text-decoration-line: none;&quot; target=&quot;_blank&quot;&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part1&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part2&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part3&lt;/strong&gt;&lt;/div&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2017/12/advanced-threat-analyticsattack.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_EaRvAb5Srxhsi3GFFDf-ncaJcJ63DfKYg2narkbaXXtrUa59PpSsfJiTkskqurn_ZVIcHnybJYJvsdTlpDosAWGhdywEtbPLaqiWCmEKwlhyHcz6xG9m9LbISIxzcEH5OF0N-t5Qc2s/s72-c?imgmax=800" height="72" width="72"/><thr:total>36</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-3858742721706317448</guid><pubDate>Sat, 11 Nov 2017 08:00:00 +0000</pubDate><atom:updated>2018-03-30T09:40:01.167-05:00</atom:updated><title>Configuring Deepnet Security SafeID OATH Token with Microsoft Azure MFA Server</title><description>&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Related Blogs:&lt;/strong&gt;&lt;/div&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Configuring YubiKey / Yubico OATH Token with Microsoft Azure MFA Server&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot;&gt;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA with pGina and Local Authentication&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Microsoft Azure MFA on-premises server supports a time based OATH (OATH – TOTP) third party tokens.&amp;nbsp; This is an alternative to using the&amp;nbsp;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-azure-authenticator/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Azure Authenticator Mobile App&lt;/a&gt;&amp;nbsp;as an OATH token.&amp;nbsp; You can see other MFA authentication options in my&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Types (Part I)&lt;/a&gt;&amp;nbsp;and Azure&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;MFA Server–Authentication Types (Part II)&lt;/a&gt;&amp;nbsp;blogs.&amp;nbsp; The OATH tokens can be added or imported prior to being associated with a user.&amp;nbsp; Administrators can associate users and tokens in the Multi-Factor Authentication Server&amp;nbsp; or the User Portal.&amp;nbsp; Users can associate themselves with an OATH token during User Portal enrollment or using the OATH Token menu option when the User Portal is configured to provide this functionality.&amp;nbsp;&amp;nbsp;&amp;nbsp; A bulk token import and configuration is also supported by MFA Server .&amp;nbsp; An administrator can import OATH Token records from an input&amp;nbsp; file .&amp;nbsp; The secret keys must be in&amp;nbsp;&lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;Base32 format&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
This blog provides step-by-step instructions in configuring&amp;nbsp;&lt;a href=&quot;http://www.deepnetsecurity.com/authenticators/one-time-password/safeid/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Deepnet SafeID OATH token&lt;/a&gt;&amp;nbsp;with&amp;nbsp;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA server&lt;/a&gt;.&amp;nbsp; I am using DeepNet Security&#39;s SafeID Classic model for this testing.&amp;nbsp; You can review different token models and details on their&amp;nbsp;&lt;a href=&quot;http://www.deepnetsecurity.com/authenticators/one-time-password/safeid/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;website&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Requirements:&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
The following are the pre-requirements to complete this configuration.&amp;nbsp;&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA on-premises server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://www.deepnetsecurity.com/authenticators/one-time-password/safeid/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Deepnet SafeID hardware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Secret Key for your DeepNet SafeID.&amp;nbsp; You will receive an email with Secret Key after the purchase.&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Review the following&amp;nbsp;&lt;strong&gt;Azure MFA Server Authentication Types&amp;nbsp;&amp;nbsp;&lt;/strong&gt;blog if you are not familiar with authentication configuration in Azure MFA Server:&lt;/div&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Azure MFA Server – Configuration for third Party OATH&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
First step in this process is to add third party OATH Tokens in Azure MFA Server. You can either add these tokens individually or perform a bulk import using an input file.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To add an OATH token,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Logon to your MFA application server.&amp;nbsp; Open&amp;nbsp;&lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt;&amp;nbsp;UI and Select&amp;nbsp;&lt;strong&gt;OATH Token&lt;/strong&gt;&amp;nbsp;icon.&lt;/li&gt;
&lt;li&gt;Click&amp;nbsp;&lt;strong&gt;Add&lt;/strong&gt;&amp;nbsp;option from&amp;nbsp;&lt;strong&gt;OATH&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;Token&lt;/strong&gt;&amp;nbsp;window.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqaRlMhc_0vvlMbtLnjq_fdAyeVvs7qrljuJmjwuRrNCVxYIl9uBUJKkRHXpDndt0eiNBYmfFKPmiRnLAOY5-5ByE0vf64jWOLIEwZkjdLx11zgW3JyxXFKSk1-E-6vkoZomCt36Bk-bA/s1600-h/image_thumb23%25255B2%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image_thumb23&quot; border=&quot;0&quot; height=&quot;675&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAcocUuFK1Ug-ZHnOkOkLxx0bi1c6OjoU7YyyS48TKJnhJ2Y2ujdyw6u_iLssoMAKU5UCP-g5srT1lNHpmCKWW-7A3pUSCWt-sR1jOtHcs8epCnbDkECVEoVGDeWG08GX7ekfTyjJmLPc/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image_thumb23&quot; width=&quot;899&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enter your Secret Key token Details&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Serial Number&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;em&gt;Required&lt;/em&gt;.&amp;nbsp; Enter the&amp;nbsp; serial number of your SafeID. This will be in the back of the Secret Keyas shown below or it will be the email you received from DeepNet.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVUSOFo7O9AiRCq14omq8xYSOEw_OTTrFU8i_lGoA6KczxdHP7Z_LXu51BRQFi-IwpM0kxNQfRfoJVC9v7Yw55DAI7SxQD2KUG03ctwa-T9St9YseFAwsLuU2IL-s6vwwV1bAKJ9NFdLY/s1600-h/image%25255B3%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;245&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA4_2DQkEJeqSSweXwzlxNpRgUaU1yprrkbRywPhMMdPKTMEi2Faw9zKuAqm-X0GD5h97yRQ40q0-ZOb1__m40WcyNf171qpFAzxstS44LJixb824eJp28I7IBPMuiWVGPMXh9nZZGgEI/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;500&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secret Key&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;em&gt;Required&lt;/em&gt;. This is the Secret Key (Base32).&amp;nbsp; You have to receive this information from DeepNet.&amp;nbsp;&amp;nbsp;&amp;nbsp; You will receive an email from Deepnet with Secret Key after the purchase&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Manufacturer&amp;nbsp;&lt;/strong&gt;–&amp;nbsp;&lt;em&gt;Optional&lt;/em&gt;.&amp;nbsp; Enter&amp;nbsp;&lt;strong&gt;DeepNet Security&lt;/strong&gt;&amp;nbsp;as the manufacturer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Model&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;em&gt;Optional&lt;/em&gt;.&amp;nbsp; Enter&amp;nbsp;&lt;strong&gt;SafeID&lt;/strong&gt;&amp;nbsp;as model type.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Start date&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;em&gt;Optional&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Expiration date&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;em&gt;Optional&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Time&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;interval&lt;/strong&gt;&amp;nbsp;–&amp;nbsp;&lt;em&gt;Required&lt;/em&gt;. Select 60 seconds.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Username&lt;/strong&gt;:&amp;nbsp; Associate a user with this OATH token.&amp;nbsp; You can manually enter the username or&amp;nbsp;&lt;strong&gt;Select User&lt;/strong&gt;option to identify a user.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5s4LXkS1YpbhxlsX0U5vwo4AwRnGtXVWJyZAcN1L9RQ0S4WizSJIPkssoM7t8CQ6OYtiXUmkTTK22Vp_ZIf9dhbub7D4cOUN_xoYUq1KKgNNsAj22AdwUK4x2ETksWxR5sE0tSjNFNxk/s1600-h/image%25255B7%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;321&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTF009UJLp0_CiS8QwX8Gp2uo2ECEfggWkQJbBAdKdEC8lqGG5KQqQlTqvK6hERlQjVqjakalzx5bN5xLPbiqeyCPiFP9dIrvB6YuoVTuOyNpil9u9SiXN7n4OizDz_OfsKgoM8oRbVDw/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;570&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;&amp;nbsp;to complete.&amp;nbsp; The&amp;nbsp;&lt;strong&gt;Synchronize OATH Token&lt;/strong&gt;&amp;nbsp;dialog will prompt for the current OATH code to synchronize the OATH token and verify the configuration.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBAF5RkrN20sjb-Ws87TFY5zmBtzsDps6M4S86xLxbDOgi5xzv2C2AWKU68BLNbb-Zs74cC6MN0omB20QkDsPy-MZ3GlXNvHPIBTUIxgSpJT5nlqe-omBD6hHCFYg8KG5pyH9U80TGEWE/s1600-h/image%25255B11%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;213&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEdtPDCmj5s57Ra6P2N7qbTcaWpXGkU4GY6ZW6IpLJEJcE1pG2vadcwJn-en8n9ol_r4N30OjXYTob363HkdsDUWlUeyYRuAh5Aevj5e7g6KnqlqESDjZW83dc0VZh8LLJDQ31TeRsqcc/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;306&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enter the current code from DeepNet SafeID from the&amp;nbsp;&lt;strong&gt;Synchronize OATH Token&lt;/strong&gt;&amp;nbsp;window to complete token configuration in MFA Server.&amp;nbsp; Click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5_0CPv6GbTYEy_FxNwIxFMuHmdZmFAyAKftLfZQX7feLlIpXlLQrPY8Qk5Q_J2EDPtwa42r-R6jiPQb6xQxHtgXD5b73GrA_sZFEi7efM92Ke-U2cSaq13H0LwAuN0t_abD_qg2UA3mg/s1600-h/image%25255B15%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;312&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGLffRgPRAxvo-0zt_hDirILrJs63LQC_NpSsZD6PeGOfMHdGeAO0_hXe35mNicrGKCy6tV7qBjZukFSlfMz_6JY5k99nMcXgFsQr1ve_RMa6zZx2fd6HkN9woaD4T6A49Ot32ppX21dQ/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;586&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;em&gt;Note1:&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;MFA server validates the OATH code against the OATH token secret key and synchronizes the OATH token&#39;s time if they are valid.&amp;nbsp; If there are not valid, you will see the following error message:&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVar-cPK8hnri5HZqnMQJlAbDEbX248_JiD5ovu-WFyUGQ6y3_rAfMl0UWPBVZXnEMS_Vvf9nnYaA8Tmtw4Ffs7QOhYlgyWdHAy-5zYK-MPRmrPk5YOU7o3n6suRrAgbC-fwEPz9bc0YA/s1600-h/image_thumb38%25255B2%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image_thumb38&quot; border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidlPPA6FMrpYlN186AApM6w5Nsl46w_n9BUhMMaQirRWkkVCjARZSOfp1a3IdbyoJ8bWgaU_rOnaVLAaLyPpFIowNkReLGCUaEPBSH1T0veeYn50GV9WEbRY5TDolMlM8BIDOwUn4DyGU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image_thumb38&quot; width=&quot;474&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;em&gt;Note2:&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;Azure Multi-Factor Authentication Server supports bulk import of token records by using an input CSV file.&amp;nbsp;&amp;nbsp; The file must be in a supported format and may be partially or fully encrypted with a password.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://1drv.ms/u/s!AOVEEHIwTxv9hsEf&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Sample Input File&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To perform a bulk import,&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp6aw9X2_p8oe8zFfS4eRJIkGFiPVM5x6V9b0T_GUfPCNAO_dQ0BaLW_6jPKC0hv0uPlspD6us9wSjPIKW2ZtL2n_kCUmHwmA_VjFh35SAtC4jnk6UeP11OtMRf9FaDaaswVg7pMqi9ts/s1600-h/image%25255B43%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;667&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFr6VpKaF7SKLkrlUaLrL-xZyn-IyE5cZ6rIwrF7hNHZgUVuQwK9PsrnhBUDK39j6tfkEeAtbo2_KvOIzoti_nMhQHi-3NXsklacW14HUI0MNRWAKwWE2fhJ2XWU5Zr5tlAD4hvMjsuGY/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;1027&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;em&gt;Note3:&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;you may receive the following error message when you click on Import button. There is an update/hotfix for this issue.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Unhandled exception has occurred in your application.&amp;nbsp; If you click Continue, the application will ignore this error and attempt to continue.&amp;nbsp; If you click Quit, the application will close immediately.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Could not load file or assembly ‘PfPskcClr, Version=0.0.0.0, Culture=neutral, PublicKey Token=null’ or one of its dependencies.&amp;nbsp; A strongly-named assembly is required.&amp;nbsp; (Exception from HRRESULT:0X8013100)&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWSNNmndCUnSLUK5K6_iosZ3xNecActK5x8vH6iavMudgAle2FdOiMJ5X1iV3kyQicxVuHBJzXfD_W4QF80FziwoUB1qVww2K1_HVD_cbfAXz1b8ZGOf4VQcrr25nti3X_y-Ko4YBmd84/s1600-h/image%25255B47%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;371&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik5ZCdzrKNd6erQqOyfBmpBtesX4qWFE8zcKztgJX6nz6WoWeEsc9d_zOea_jNWFBpHdQFeviXCVv7V_kx1poMAPFk7zYj1nNFgFZzp2EYLUHzTPD5b8IltdBvNGpiHaUynJ1V6SG2FOA/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;462&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Azure MFA Server – End User Validation&amp;nbsp;&lt;/strong&gt;&lt;strong&gt;Using DeepNet SafeID OATH Token&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
The final step in this process is to validate the DeepNet SafeID configuration and authentication experience from an end user perspective.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To configure OATH token as the authentication type for an end user:&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;From&amp;nbsp;&lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt;&amp;nbsp;UI, Select&amp;nbsp;&lt;strong&gt;Users&lt;/strong&gt;&amp;nbsp;icon&lt;/li&gt;
&lt;li&gt;From right pane, open the user properties by double clicking the user object.&lt;/li&gt;
&lt;li&gt;This will open&amp;nbsp;&lt;strong&gt;User Properties / Edit User&lt;/strong&gt;&amp;nbsp; window as shown below.&amp;nbsp; Make sure that the&amp;nbsp;&lt;strong&gt;OATH Token&lt;/strong&gt;&amp;nbsp;is selected as the authentication type for this test user.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLtXg1s2YVQPjpu8YGNimGnrHS5qaQCTC5rq0aW7PADXtPTdYJGxh8tA-I14dz77QgT9-JvxV_wDP0logAWvU7w0mmz8aVaJFFSAonffhRtICByX4eBEhZuXaBhNnJ_IFaOd3lTutD6IA/s1600-h/image%25255B19%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;606&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6Jj1WmEOMhjcAXQbHWZMnXXZn7RG40ecoNZxl4OVJStvUO9Qs863P5v1k72cBlWowJOKknI1WRdfHu1kcnaJe6eoexlEhP92X7ijUTiebOku6G2sxxZ8-1sSUz5jO2Ypnl44GKQ21CI0/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;678&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;To validate this configuration, select out test user object and from the bottom of the window, select&amp;nbsp;&lt;strong&gt;Test&lt;/strong&gt;&amp;nbsp;option.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSxQHMLNs0RJATOSRHmeMrcUH3zMGJ9YJca7lU7A8EVUJ_thulepMB9FUj4muC-hiYvloM9uCXYa4VjKOGBaAl-Clnhf9oOt6sXRGnbLbC_h0Wi-Xub8OzXlHXT0uwKab1SwRy_A248Mc/s1600-h/image%25255B23%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;668&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvV3FNId7spl0GmIx5gpPB5Auhs1A4TErNFs8AgopYOp2Bl-WxNwqNqvQcTL2suax7t-PmhQQ1gDFPuhuUteQFqOVPO98vsmvVwf_ShhM2ASg1c_xtLB8QATGxMUcsjBc8iNhulXBunPU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;1029&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;User will be prompted for first /primary authentication using a user name and password. Enter the&amp;nbsp;&lt;strong&gt;User&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;name&amp;nbsp;&lt;/strong&gt;and&amp;nbsp;&lt;strong&gt;Password&lt;/strong&gt;&amp;nbsp;for the user, then click&amp;nbsp;&lt;strong&gt;Test&lt;/strong&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHtgyg6ZwzGfL9MG33zWn9oF54ktjlVVajgMuJ0u-_nxQrV1312HUjhauquvrlnHyrP55lkEaCN-vqdnlxaaDAoCkngOIHL-H_5_5tCRBFIPo2k8pb4ZQspBcvGC24VYmVbDzLvJ0N4Os/s1600-h/image%25255B27%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;192&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUn7rAjyYVeO2wWvfGi1Pg9APF6Md1H1AaFTJBHR-DAnnPSzP4y0lib7Zsrf2n3a2ABT-4jhqH6TNJDpjRt_DXmll36leSfBWA4rS-4OeomVnLgzJmosn-OKQ3DQROCLa160OtvrRKiHw/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;415&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Then it will prompt you for the secondary authentication.&amp;nbsp; In this scenario, it the OATH Code.&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVdAe0OIJacfNNJH4KJqCNqMLpIUloB4BGPohWUvI13gL7Al02WhcQ2DgJUc6fys4vUKKIAFgPYBPUTCIQUqZS4feTxoweTIm5-oWBx2PkJtyiFs232XLWZqJwfkzoYSlcbr9FiEGH_TQ/s1600-h/image_thumb52%25255B2%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image_thumb52&quot; border=&quot;0&quot; height=&quot;139&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW6oaao-0TAaHshWKSkBTHkgxHWHHweh9qF2d83J_5BTqO37FtLKlgR2rFuEfQD5wm0uOXPBnRQjEAk_EAjaptSxwKdeaOqTgSdQo-xzHcIEasQNvC5KClztJ6bt9e-wP7YVsX6XjmIDU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image_thumb52&quot; width=&quot;317&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Get the current OATH code from your DeepNet SafeID.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHvHpbO6MDOCyIi811lAaZFuHnLzH0R8hT-L-4P6ydq1fhU-LPa8q6ZkU5RsL3qa5E60iXNGpy-o6OE7ixTs1oSlfxGPv0Tl2b9PuQNhaAefHPSKEmTFFXn8RYM7V4leavNWe0e3Ut2to/s1600-h/image%25255B35%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;312&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjv-eXUVEXhrCGBYH3P_t7wwjS1X6wgzuH4XF3ctbApICIHlQdFEBzmjNew9OxzUY5h_SRwBXczun7neRAofWSHquSqudfj6IdwUMM8UM7XWjCmXN-VnnXTqubSCcLVaHVlzlf-9dB_jLc/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;586&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enter the current code in the&amp;nbsp;&lt;strong&gt;OATH Code&lt;/strong&gt;&amp;nbsp;window in the MFA application .&amp;nbsp; Click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRkEtgwxNHnE8PtXEJgSoh4wa8rxMZUJNeM6kihQvnMlSzEKQraShFoIYPceHA0A8kVF0uKKx14QsCCA5Lh1GrX2nZbHBXQYUlpcaY8lNUoLB_2Ekd-Clxz2cj3e0GJRizTUm90QxKPIU/s1600-h/image%25255B39%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;136&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3lg7LeYupmHxTkZXAfZc65Bo52ON9mLKQosNlzucQX71WNbYWBaklBQ1ny61x9TKltJH7cKn92SAUpElGMDdMNb4MsWTHM6BFFihn16zyqenBfdLCXt9GOsJX35_1r9mTWdPo7G0YJpw/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;313&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;You will see the authentication status/result as shown below:&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRRhZ57zr-QYUH83lURnUe6ZWa3HjtveVW8hxv0RF8aj6KMTNMADAp8ndWW9IHyYwQ3gCC21Dr_xUSYeG4aL2Mgp2dMgkazzGbd4PEey1fqEg9fBS9xwMMAJmVmdF_54Jqalwa07eE-Tc/s1600-h/image_thumb49%25255B2%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image_thumb49&quot; border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaeWuOFzLWGL7m2fHno3Y8GgnMZaq7kiQA13BAbD5KIIfkkzYPyVUmmFEgq-wj_brtdU6GzOoyabNCrtYb1an3eCTKnQrlxboumzCDB8D4RvqIxVl5ZTcCRGb_wG4MoB9ih23cUIZ9WHo/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image_thumb49&quot; width=&quot;263&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Related Blogs:&lt;/strong&gt;&lt;/div&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Configuring YubiKey / Yubico OATH Token with Microsoft Azure MFA Server&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot;&gt;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA with pGina and Local Authentication&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2017/11/configuring-deepnet-security-safeid.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAcocUuFK1Ug-ZHnOkOkLxx0bi1c6OjoU7YyyS48TKJnhJ2Y2ujdyw6u_iLssoMAKU5UCP-g5srT1lNHpmCKWW-7A3pUSCWt-sR1jOtHcs8epCnbDkECVEoVGDeWG08GX7ekfTyjJmLPc/s72-c?imgmax=800" height="72" width="72"/><thr:total>26</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-3364285146806403164</guid><pubDate>Fri, 13 Oct 2017 07:00:00 +0000</pubDate><atom:updated>2018-03-30T09:42:13.329-05:00</atom:updated><title>Configuring YubiKey / Yubico OATH Token with Microsoft Azure MFA Server</title><description>&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Related blogs:&lt;/strong&gt;&lt;/div&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
Configuring Deepnet Security SafeID OATH Token with Microsoft Azure MFA Server&amp;nbsp; -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot; title=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot;&gt;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&lt;/a&gt;&lt;br /&gt;
Azure MFA with pGina and Local Authentication -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
Azure MFA Server –Authentication Types (Part I) -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;br /&gt;
Azure MFA Server –Authentication Types (Part II) -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Microsoft Azure MFA on-premises server supports a time based OATH (OATH – TOTP) third party tokens.&amp;nbsp; This is an alternative to using the&amp;nbsp;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-azure-authenticator/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Azure Authenticator Mobile App&lt;/a&gt;&amp;nbsp;as an OATH token.&amp;nbsp; You can see other MFA authentication options in my&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Types (Part I)&lt;/a&gt;&amp;nbsp;and Azure&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;MFA Server–Authentication Types (Part II)&lt;/a&gt;&amp;nbsp;blogs.&amp;nbsp; The OATH tokens can be added or imported prior to being associated with a user.&amp;nbsp; Administrators can associate users and tokens in the Multi-Factor Authentication Server&amp;nbsp; or the User Portal.&amp;nbsp; Users can associate themselves with an OATH token during User Portal enrollment or using the OATH Token menu option when the User Portal is configured to provide this functionality.&amp;nbsp;&amp;nbsp;&amp;nbsp; A bulk token import and configuration is also supported by MFA Server .&amp;nbsp; An administrator can import OATH Token records from an input&amp;nbsp; file .&amp;nbsp; The secret keys must be in&amp;nbsp;&lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;Base32 format&lt;/a&gt;.&amp;nbsp; This blog provides step-by-step instructions in configuring&amp;nbsp;&lt;a href=&quot;https://www.yubico.com/products/yubikey-hardware/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;YubiKey OATH token&lt;/a&gt;&amp;nbsp;with&amp;nbsp;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA server&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Requirements:&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
The following are the pre-requirements to complete this configuration.&amp;nbsp;&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA on-premises server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.yubico.com/products/yubikey-hardware/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;YubiKey hardware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.yubico.com/products/services-software/personalization-tools/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;YubiKey Personalization Tool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.yubico.com/support/downloads/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;YubiCo Authenticator Application&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;YubiKey Personalization Tool – Installation and Configuration&lt;/strong&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Microsoft Azure MFA server supports only the&amp;nbsp;&lt;a href=&quot;https://tools.ietf.org/html/rfc6238&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;OATH TOTP (time-based)&lt;/a&gt;&amp;nbsp;tokens.&amp;nbsp; So you need to make sure that your YubiKey is in&amp;nbsp;&lt;strong&gt;Yubico OTP Mode&lt;/strong&gt;&amp;nbsp;using the YubiKey Personalization Tool. Other configurations are optional for Microsoft Azure MFA server configuration and testing.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
The&amp;nbsp;&lt;strong&gt;YubiKey Personalization Tool&amp;nbsp;&lt;/strong&gt;can be used to program the two configuration slots. Also, it can be used to personalize the YubiKey in the following modes:&lt;/div&gt;
&lt;ul style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Yubico OTP&lt;/li&gt;
&lt;li&gt;OATH-HOTP&lt;/li&gt;
&lt;li&gt;Static Password&lt;/li&gt;
&lt;li&gt;Challenge-Response&lt;/li&gt;
&lt;/ul&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Download&amp;nbsp;&lt;a href=&quot;https://www.yubico.com/products/services-software/personalization-tools/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;YubiKey Personalization Tool&lt;/a&gt;&amp;nbsp;and run&amp;nbsp;&lt;em&gt;&lt;strong&gt;yubikey-personalization-gui-3.1.24.exe&amp;nbsp;&amp;nbsp;&lt;/strong&gt;&lt;/em&gt;file to compete the tool installation.&amp;nbsp;&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Insert YubiKey into the USB port.&amp;nbsp; You may see the&amp;nbsp;&lt;strong&gt;Device Setup&lt;/strong&gt;&amp;nbsp;windows as shown below.&amp;nbsp; Complete the drive installation process.&amp;nbsp;&amp;nbsp;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsijlDY12UgDj4KmDajzJDYl60qqoT3tEOS256NT2BMvtNt5b_3wF4QrKO-eszmjERx4GDHzAcKZV1bF94EiN2XJPXRZ5iZA8TpWE8t-6Vxr3xWtY7nh1aZ8B3ojBAD26aWxQ1qji9Qb0/s1600-h/image%25255B6%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;312&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDg9aRfj3Tm7gYmkSivDkfb8ZIxBgg4ex66ZORmhGtZ87FxhdwiX6eyLsb26sdHHXFHqshm1AO4nb4BeEEXHrBlGEO7AHvq4q3r3tbuxEeo6Y4ys5gckloz0LKBSlCvJL9DRVBxYRIMAE/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;618&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Open&amp;nbsp;&lt;strong&gt;YubiKey Personalization&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;Tool&lt;/strong&gt;. Make sure:&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;YubiKey Personalization&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;Tool&amp;nbsp;&lt;/strong&gt;has successfully identified your YubiKey.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgglq8r-6wyepPEefwu0QPI9-No_F31aNRkHvsjcV35r7uuR2vBb3FuSxMvBdb3TdmztKrcNYJN3G97tCc4cVQKe1a4CIJTAyHuuOl-hqBxAN_4Jerj3-Nqz_1v4hHEDHORSYsyLDVL5ck/s1600-h/image%25255B14%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;237&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3OCvpgUZ_GvdoPI0ySGFUWPhOfbKvvHzQPa-CSsMaBEtcQqdJ7KzSDX4fiDaGhuZ5ArtOlhycaCKCybztoFs5ip0NdV73pXNKqPkrhxftkbaw4TDVpUndGZcesy5solDHE2Elj-Uf9VU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;903&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Yubico OTP&lt;/strong&gt;&amp;nbsp;displayed as supported method in&amp;nbsp;&lt;strong&gt;Features Supported&lt;/strong&gt;&amp;nbsp;section.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-5gAsaXBcI9QcSHw1TW1d3yZT_bXdEzmlcNOhcz2V7CSsSSGJFsfdtMTS_Tt_fObG6xLNig9G5QSPYDkq_6yrTpQe78hsqetPLFOeTNOy7zU8VbnUC5szIn4ywWUnz1e8n5eBKme5iEQ/s1600-h/image%25255B20%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;231&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE9M2nuYXviqKoq7V-B-Rpd8YgQSJOW5qACDx_KDmzK6gFzCrWP1IpV60Rxh4oP0XdT9PiD9RA3rfUFUb9HglqGelZ0oesy4QJG28jSzoL5QHMnUsxHFYEtlTWLpSdhR4vlz01srQ-vCg/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;174&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;You will see all the current OTP configuration in Yubico OTP tab shown below. I am going to a use the default configuration for this testing.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTkAHVJp1sPjKzdBcvGUxTyAvMkxOmmPAG4LwraP5w-rZmxUDNv_wmQAmCxTve8iyQXkCylkf582VPr8Af1uHoFZQ6Oonvy3vbae5kk1Z2tn3U8Et3NLP4qtd0cjiS8H3rZa_8zq10_ug/s1600-h/image%25255B24%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;438&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrtKnC-wtHswrUDNW7_B33fi4afHq3amXwyDFSInU1irFaoVV25jok_jIX8TxOJUy6mDQ7oooIlbhf9WsSLNHxVyZxtlMuZo6DswItbt0ckd2z4EjeLOHrTCumStnHJli75c8M-9aJOWM/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;720&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;YubiCo Authenticator Application – Installation and Configuration&lt;/strong&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Download&amp;nbsp;&lt;a href=&quot;https://www.yubico.com/support/downloads/&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;YubiCo Authenticator Application&lt;/a&gt;&amp;nbsp;and run&amp;nbsp;&lt;em&gt;&lt;strong&gt;yubioath-desktop-3.0.1-win.exe&lt;/strong&gt;&lt;/em&gt;&amp;nbsp;file to complete the application installation.&amp;nbsp;&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Open&amp;nbsp;&lt;strong&gt;YubiCo Authenticator Application&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;From&amp;nbsp;&lt;strong&gt;File&lt;/strong&gt;&amp;nbsp;menu, select&amp;nbsp;&lt;strong&gt;Add&lt;/strong&gt;&amp;nbsp;option (&lt;strong&gt;File –&amp;gt; Add&lt;/strong&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgO4kMxAUqRKA1ppDwsIC62LIOZPn_XWRoCuln_cQCbiu_P8xx4CVBPlxN2ObbeR1o9HJif3OIsomZX8eA7hPXNgciiiEPScONw99VhlJ0N5jAvV4E1b_rLNosUvVSHkXccVJLcfFiSg4k/s1600-h/image%25255B28%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;174&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi90TMBqmoKLWIiuPgd-MTmQrApPH7rnWf4EvCcltDjd8Trvj_6yN64HBT-Xnyi9ZXoCkXwXqGJlYdUp64aJoUDjhyphenhyphenfBJN8kap0FzK4RQqd6NrBjYumkivTKlxga1x-p1FwNs2ae1bqRec/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;329&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;From the&amp;nbsp;&lt;strong&gt;New Credential&lt;/strong&gt;&amp;nbsp;window:&lt;ol&gt;
&lt;li&gt;Enter&amp;nbsp;&lt;strong&gt;Credential Name&lt;/strong&gt;&amp;nbsp;– An identifier or a display name for the credential.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secret Key&lt;/strong&gt;&amp;nbsp;– It is a Base32 key.&amp;nbsp;&lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Review this&lt;/a&gt;&amp;nbsp;If you are not familiar with supported numbers or characters in Base32 encoding.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Select&amp;nbsp;&lt;strong&gt;Time based (TOTP)&lt;/strong&gt;&amp;nbsp;option.&amp;nbsp; Microsoft Azure MFA server supports only the&amp;nbsp;&lt;a href=&quot;https://tools.ietf.org/html/rfc6238&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;OATH TOTP (time-based)&lt;/a&gt;tokens.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Number of digits&lt;/strong&gt;&amp;nbsp;– You can select 6 or 8 digits as OATH token length.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpTmWD-lvVaZ6_KLN_bZC2cDoko2zx-DAYclBWA2ijvFmUXvW6i3DeqAnY1kyY7uPVIc4ookHIxHsDtmqV0MtsikzN3wtUAWFEcKJ5yrZtQlYarpxu6az3rMNe_sfyMgAjiNHQ3nHj4Bo/s1600-h/image%25255B39%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;208&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrfUUPwBOLl2CawtgOD2jiEYapeDhbtA8C27EIyNRJUQT2ZDtl0KZEj3rgPH2kO2XRJkyR9pKcqPiefr1GcPa2NDKtGy3YbDF3AzIsNGad0Ncq_Qc-MN6Zrvka7c8aQGdXVDwDWReoQZc/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;329&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Require touch&lt;/strong&gt;&amp;nbsp;-&amp;nbsp; If you select this option, end user has to touch the YubiKey to generate an OATH token.&amp;nbsp; User will prompted with the following message:&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimu6PgCghWnlqwzlseqnMgmWnSrX_tK3sADrNw7Ed01st66qHWnBnJnJ5hPighnFKDCUwVWHblGlWldEwDNquQdZ3xzoN1emoF6VX9SQU9Rp9sU5JOdOAhsgnR-pD8z5LPQzEZMvZ4W_o/s1600-h/image%25255B31%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;101&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfeYy3HXcD1p8CzajZBlhqXwVbs_LkiNw01Bw7SXeNUebM8fc9UBpWrwoO3nGPwbZyNcJ-58VSgEhL8FggBiepBFedi8VTKul7fA9psTJS9uHfHgP__MdVCDGiT8reml1IjwoiCuokErU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;210&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;&amp;nbsp;to save the configuration&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjHzAGwMGGMeRp1uPzfAxrMyRHq2GPy7ZkeFsgqoYN1uoVxWsGAmuDxPhyLLrwzEtFaodTpMiWdPJgxCsne9ZZSz1ZOZqs9NExLcyvAKDgSJshFJvFwFVaBtvNegWrx8IG4ejrQBLd1Ck/s1600-h/image%25255B43%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;282&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQtT7JZGo6mHLxdFnVQeQqknwHVeg7s5zyx9hwgUusTma6wXz3KCID-rE_9n6hfPKz986dNiONpFC-esKTs2BSudVUu5PAPdfoPdzXKTR048Nvp3zu32HiLq06jGl2qmQzkhoebaGzb4o/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;269&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;You will see the newly add account in the Yubico Authenticator window.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip6JCyDzRZIk35AhQRKZU0QoI_BxgSHXrs1hkkY0AfFHo94SVeG1iF09Y5SIbMcAa9kbjgZN21WjtHtKfmIK_-txT0To4rviT8q7m1PQApjGJDlypHIXsCLWFkS_XWzNvJr1q42khH6yM/s1600-h/image%25255B47%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;150&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkONPCn31P7bTHSoa-KyiycRsgyo8desblo7Nn85khxH9QVAAQjFm_BQOZa2Yu9q9N3WyYc-LCbLgprzY5E9WNdBaI55DimvqDBjhadayxdvRSYMyd0TllIHLbrlEStMhHO-Ksk9auLUE/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;328&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Now we have completed the YubiKey account configuration. We can move on to Azure MFA server to configure the OATH token.&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Azure MFA Server - Configuration for third Party OATH&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
Review the following&amp;nbsp;&lt;strong&gt;Azure MFA Server Authentication Types&amp;nbsp;&amp;nbsp;&lt;/strong&gt;blog if you are not familiar with authentication configuration in Azure MFA Server:&lt;/div&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;br /&gt;
&lt;span style=&quot;color: blue;&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/span&gt;&amp;nbsp;-&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To add OATH Token in Azure MFA Server,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;Open&amp;nbsp;&lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt;&amp;nbsp;UI and Select&amp;nbsp;&lt;strong&gt;OATH Token&lt;/strong&gt;&amp;nbsp;icon.&lt;/li&gt;
&lt;li&gt;Click&amp;nbsp;&lt;strong&gt;Add&lt;/strong&gt;&amp;nbsp;option from&amp;nbsp;&lt;strong&gt;OATH&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;Token&lt;/strong&gt;&amp;nbsp;window.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMa0kFX0LV-nEHGmJNArs3gI0pgTk9UbWh7uLaZ0SxuE3AbDjN_mLLj9uE9qsOvvMpwH49odAZEK2027w4fFaMIroj44ePhVRSZ_InFNfyyddfnsyITEvZeGG00xkTBqifcv6M1zFwIjg/s1600-h/image%25255B51%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;675&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF4q67QDagL8jjwHczuLipXWG3_4fvEcS1ESDhRt2-kPbNAPAmHVv_jJ2sLG56H-7vAnmgFBkcFZFX2ULynKgIlqsOdZhNA-OjwRXiSm0E3YQre7FIz3W-wkUekmoc_CdblytFVvpBq4g/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;899&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enter your YubiKey token Details&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Serial Number&lt;/strong&gt;&amp;nbsp;– Required.&amp;nbsp; Enter the YubiKey serial number. This will be in the back of the Yubikey as shown below:&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgckrjKB1l_4HmaTy5bkVIH8eUmlm1RCp33yDZpxwLGwAgQpyhFAyD3jv8p1tNXHmY-r3Dvi8qhwTcpZ111iwkf5gEHbYHH7jhmbnTDkzUqO8JWxaywNoAYlBHA0wz16rzQERDnZWNRCrE/s1600-h/image%25255B54%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;244&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtUx4sY2mdn9ukE4ZXiPWnbay2iqfKXxfbzbHaoN1slUJlyby01k1d-3qByJn2Ix_YpFNcUqk6uOJyurdXJUeKpxrGd1gex4pRNQTi2iNBNdfES20IvSHRS66MCTRlhT7O3V1l0NGXUTM/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;126&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secret Key&lt;/strong&gt;&amp;nbsp;– Required. This is the Secret Key (Base32) you have configured using the Authentication Application.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Manufacturer&amp;nbsp;&lt;/strong&gt;– Optional.&amp;nbsp; Enter&amp;nbsp;&lt;strong&gt;Youbico&lt;/strong&gt;&amp;nbsp;as the manufacturer.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Model&lt;/strong&gt;&amp;nbsp;– Optional.&amp;nbsp; Enter your YubiKey model type.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Start date&lt;/strong&gt;&amp;nbsp;– Optional&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Expiration date&lt;/strong&gt;&amp;nbsp;– Optional&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Time&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;interval&lt;/strong&gt;&amp;nbsp;– Required. You can select the default 30 seconds value.&amp;nbsp; By default, YubiKey changes the 6-8 digit code&amp;nbsp; every 30 seconds.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Username&lt;/strong&gt;:&amp;nbsp; Select the user for this OATH token.&amp;nbsp; You manually enter the username or&amp;nbsp;&lt;strong&gt;Select User&lt;/strong&gt;&amp;nbsp;option to identify a user.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;Click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;&amp;nbsp;to complete.&amp;nbsp; The&amp;nbsp;&lt;strong&gt;Synchronize OATH Token&lt;/strong&gt;&amp;nbsp;dialog will prompt for the current OATH code to synchronize the OATH token and verify the configuration.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDUSzo7qKW-rxD0k9Lq7ulyJIrE1SEmQ8dooo7WDT6MRKO7rHHJZSNanPz3Vf7rxQ8zuaVmGdmx_7noOgvBpMbfrAyxFbEKdIGEWe0CcTBvPTv8XXu59XmMNTmeWOGENOtBlgC6PdOgFE/s1600-h/image%25255B65%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;216&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX6UHJAf_Eg9t7OXF-4I9BhhcSgUsqjxhc-9Z2wBHFSCzxdOTQdGApUfKcb30aSP6w6IAVBl-6NUBNwAasddhS8EP_GCflTzQtWkfVloSqxnXcoi1DzPjnBLy_cQgjTSA0Ovj_jzIlEYA/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Generate a new OATH from Yubico Authentication app using the&amp;nbsp;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYQiYX46A60qTWOfQrib5ycoM6qohrz5QdgaSWo86wU49aLVFJ5-S5ZFBFOo-3tGOa0i5MxZPXgZHTCv1v_Nii9p2NFK-h02bULFBYSefsd3VXtzezKMUUXbKYzdLyQA1rwr5JcZjvcTQ/s1600-h/image%25255B74%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;32&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhWaIDK6F2O9jPKWGsdq-Mkvfk-yS-9MD_ExfAU0roiCU0Oo_Y7p0D2xx40-2V0c-937KqQHR__6godLOZS5a8VO7KRXs6MrlXAD4aIXJDWEEplKRAQWUe_DpExNgaxj48d1JSH77zmil4/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;35&quot; /&gt;&lt;/a&gt;button.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWegOfvFuSzEPMzszZjVyOGYB8AuBwt6fEM2BbYJgJSIJo2kNBVfXDL4DHZ_nFyWWAglemIqEd812NBK1-dE0F0d8rLJa5ajlE1ui7XLwP9SZ7oFgS11k1c4ry76vGztSlGe406cRL1Lw/s1600-h/image%25255B66%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;246&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEing_BZ8aab7vBDvebpL5qJhQ86uc-jYrBYrAi7EP3brmCdLnEPkUad9R70_-xNQOCKv7g2ytyC315wKu6QtOBtHMJOBudn7FoLwH-ySDHBj7nFOf6IAkVGcGkqAjPE-GDra6sSbDAajkY/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;325&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enter this code in the&amp;nbsp;&lt;strong&gt;Synchronize OATH Token&lt;/strong&gt;&amp;nbsp;window to complete token configuration in MFA Server.&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;em&gt;Note1:&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;MFA server validates the OATH code against the OATH token secret key and synchronizes the OATH token&#39;s time if they are valid.&amp;nbsp; If there are not valid, you will see the following error message:&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjm1by2zJJXlxX5hld0KHdP11ItO2NWLBYHfUnR8uJaqH1DeiNukaXNWxHWZM2U2RuNsIxUU3APw4HAIh_J0zvQ7wZqR4dj6KygykFmsZTHS_gZgLMXT2NA3MC3nvWzmPJdgV7jebtLrik/s1600-h/image%25255B78%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQvaOc2QJ4764Afu3FMX8TUklVGPVYvFbZ1Z2BLmVJaxPcxUU2ltlSTSYr0Z5MISr0FRK7yJB3EII0BqDoTsJakHpBq6vBFxNkWoii3ihYX_nm_8AqVkKbIIrNYZuFnR8EbRyrQREmGW4/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;474&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;em&gt;Note2:&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;Azure Multi-Factor Authentication Server supports bulk import of token records by using an input CSV file.&amp;nbsp;&amp;nbsp; The file must be in a supported format and may be partially or fully encrypted with a password.&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://1drv.ms/u/s!AOVEEHIwTxv9hsEg&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot;&gt;Sample Input File&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To perform a bulk import,&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Select OATH Token icon and select&amp;nbsp;&lt;strong&gt;Import&lt;/strong&gt;.&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;&lt;div align=&quot;justify&quot;&gt;
Select the input file and click&amp;nbsp;&lt;strong&gt;Import&lt;/strong&gt;.&lt;/div&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaenOyT-r8JGaQ5qya2Q_vO2sLtuLLhYHB2LE1xsewlNQFMB-FW5WSxZikFiGekdDbFGwySoyJ1pIpaitjLpiEwIu_BdbT4M_d_F2P4GLRNEFUJNb577fBOU0USXiF4lUgwhg3hWK8Jdc/s1600-h/image_thumb%25255B19%25255D%25255B2%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image_thumb[19]&quot; border=&quot;0&quot; height=&quot;667&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglCpp8Hu2n7WQ52r-4X1L3J_ul-Pqi8X0XYbzUbProRCgUMawAYczh4goqqLzPtAtvKwUjjRUd5J4L5FAIbfmNI7k1QDhezC-lBF4jgKLtccUtM0NlSiaom5vTnChO5lwfw-QJIAWtjRI/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image_thumb[19]&quot; width=&quot;1027&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;&lt;em&gt;Note3:&lt;/em&gt;&lt;/strong&gt;&amp;nbsp;you may receive the following error message when you click on Import button. There is an update/hotfix for this issue.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;em&gt;Unhandled exception has occurred in your application.&amp;nbsp; If you click Continue, the application will ignore this error and attempt to continue.&amp;nbsp; If you click Quit, the application will close immediately.&amp;nbsp;&lt;/em&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;em&gt;Could not load file or assembly ‘PfPskcClr, Version=0.0.0.0, Culture=neutral, PublicKey Token=null’ or one of its dependencies.&amp;nbsp; A strongly-named assembly is required.&amp;nbsp; (Exception from HRRESULT:0X8013100)&lt;/em&gt;&amp;nbsp;&lt;/div&gt;
&lt;div align=&quot;justify&quot; style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI1lpdSfWrK3kPXSakF-XdllhCceEGch5EUekRpYG3pzMzKQ-JcRMKwQajoT_x6T0lz4zWSojl-MSFELVg0QbHwiePoeb8LO4o5Fe5VoMpleyorkouXCCp4beNBqpsQgAw1JicOeP5HwM/s1600-h/image_thumb%25255B21%25255D%25255B2%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image_thumb[21]&quot; border=&quot;0&quot; height=&quot;371&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0cv6FLw2WsUNjLusJySN0sWNdNKuhPJ-DQzo0nRUZRicFYwj2W51aD9-XzY9Qt67xCPJfA9_SO-MJBc_H_ex9I9I1j_nTPX3Tm4hpFu1vKbKhNHieJTnOhmIphUSrkX4halSeITjMLUE/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image_thumb[21]&quot; width=&quot;462&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Azure MFA Server – End User Validation&amp;nbsp;&lt;/strong&gt;&lt;strong&gt;Using YubiKey OATH Token&lt;/strong&gt;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
The final step in this process is to validate the YubiKey configuration and authentication experience from an end user perspective.&amp;nbsp;&lt;/div&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
To configure OATH token as the authentication type for an end user:&lt;/div&gt;
&lt;ol style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;li&gt;From&amp;nbsp;&lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt;&amp;nbsp;UI, Select&amp;nbsp;&lt;strong&gt;Users&lt;/strong&gt;&amp;nbsp;icon&lt;/li&gt;
&lt;li&gt;From right pane, open the user properties by double clicking the user object.&lt;/li&gt;
&lt;li&gt;This will open&amp;nbsp;&lt;strong&gt;User Properties / Edit User&lt;/strong&gt;&amp;nbsp; window as shown below.&amp;nbsp; Make sure that the&amp;nbsp;&lt;strong&gt;OATH Token&lt;/strong&gt;&amp;nbsp;is selected as the authentication type for this test user.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6ax6nNbm_7wtINhmwHnNRE2LShJ0Xd05CIigEiZcXXKggKCQ5LOsQN4L3ghglJSsKu64hCG90V4RmE-h6zv5-lN6zGpoiTqgQoKbNfsHog8hz7_-mjvt0EIZX-vEPmQvVtXRF8gaYqrk/s1600-h/image%25255B90%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;607&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo1axRp5AhxMDvmXb7nvpstVkUVl3qWuks24f3C2Q9bnqRh3OibBidGy8mMsFExfRS7lfNR48RCCUFncmFLsqbwYSguP-SU4shGdIggdfSBHUSWRRFolSxNcxrwQXGWp91VOh67ITGaAs/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;678&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;To validate this configuration, select out test user object and from the bottom of the window, select&amp;nbsp;&lt;strong&gt;Test&lt;/strong&gt;&amp;nbsp;option.&amp;nbsp;&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLZYkj2G6_io_XSyD770NAxoKABvnfcmKBObMIQSlfti4KYfuhkVeRK9ihdEHoFF8Vy6KHG2Z5o1cShflLp_Adf_YIeeQp6R4NX8MFIc97yfbBa1CC7NQRSoNlCsyxffYt_VeuWtM9b7E/s1600-h/image%25255B4%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;674&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlTIiPL6x0XS8miMfLmQ4NddBrpCkAnXlqMgNI0lVQabYmXzIAXm_WgognmTmdKyY6mfM9IYjzKC_EqjMKdq7bE1E8sfTQgtwsV5gjmlzpkGtNu5fCXSLs9WgWkeQFEyLSouNRpPH3Lhc/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;1029&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;User will be prompted for first /primary authentication using a user name and password. Enter the&amp;nbsp;&lt;strong&gt;User&lt;/strong&gt;&amp;nbsp;&lt;strong&gt;name&amp;nbsp;&lt;/strong&gt;and&amp;nbsp;&lt;strong&gt;Password&lt;/strong&gt;&amp;nbsp;for the user, then click&amp;nbsp;&lt;strong&gt;Test&lt;/strong&gt;.&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVBvC2BV6esgq4Ll8hrMFGUll-5wEkV-Fx5ZlETnD5mnZLAn58MZbJ52BS5f_Q3qqS7jzxA5D0pOqZrFJkvcYHPMYxj3OAC9ZVSvBogqZ-VBOStrySjIxL5KF65uoEalPC1MJ-FYo-R3k/s1600-h/image%25255B94%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;195&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZRwAA1jDHpjuDigXa6Rll8gzl-btXYrBSBarGZ-nv0sclKpkR3KFJIlRuNGaohRyErwI1wpoqLNUxeY__IV3iivQsxVKDi3nsf7kYccAovJfG7NAFLuPlWuyPa9me_InV7kyAU53IjPs/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;417&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Then it will prompt you for the secondary authentication.&amp;nbsp; In this scenario, it the OATH Code.&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgThvUzKuIehr7TLCJNknJ4TiT5B-6JlUqjHw5iog7rnoMWCtop4R_mPv_d_F5S9t7bXLqzu_KqepiXRiMhBl00eKPqydeKdqxHEnnq96BCRIlNoin_hw3bfJHdiwXExo9RJPQniG41zbE/s1600-h/image%25255B110%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;139&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinBbM0Bx7uKkRU2HWL5wd_matwf9BSqmGkbVSHICutTJzDz6k0rUbX26zjahAXz53r06oSt3EQMEtaDqfEPgmQW1TYLay201k0y7pB6isdMrORaMLO8JGLgCMiNXh5T3TZmPf2kbENmPE/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;317&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;To generate a new OATH code, open&amp;nbsp;&lt;strong&gt;Yubico Authenticator App&lt;/strong&gt;&amp;nbsp;and&amp;nbsp; pressing the&amp;nbsp;&lt;a href=&quot;https://www.blogger.com/null&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;32&quot; src=&quot;file:///C:/Users/SanthoshSivarajan/AppData/Local/Temp/OpenLiveWriter1425683934/C9F885A12646/image.png&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;35&quot; /&gt;&lt;/a&gt;button .&amp;nbsp; The OATH code will be displayed as shown below:&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz1X58WfXF94-3gRUsIu0LiBtWWC32hAf5uGJmoghAHDfi6ptZK76cIuTeOvjFbhCnqQJFEDcrsow0s3705pvLwwAu3-25VxQO8IF7125UVLBxIk_v1x9CIaCCcVlkjS4L_VU16HBMkO0/s1600-h/image%25255B109%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;168&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbGMicA3SPj2klUGQjT7tKSh8WziDj61WRjqVMXaK3Dkai2M-rt8Q13FZzzLxJhoE1XLK1CAveJL_o9xViX_zCK0_CQngNg0ITUhhLaeR4cRXPfi20c_fYL_V1CXnRA1uhx6IaNu-ZWiw/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;335&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Enter the current OATH code in the&amp;nbsp;&lt;strong&gt;OATH Code&lt;/strong&gt;&amp;nbsp;in the MFA application window.&amp;nbsp; Click&amp;nbsp;&lt;strong&gt;OK&lt;/strong&gt;.&amp;nbsp;&amp;nbsp;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4deyImwMykoAikbWkE1-TmSQQvOuldIq9QgGzbpBRxrhzSN7XzMwHA7uphUtsdMlMMjlPWaboNZuqV6tWU3Ux8U_bN3gWsDPBjlOaYu_8IpT41L765dJ8jf7vGRJKlH8Ds5lYel0jMlw/s1600-h/image%25255B108%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;142&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdo-CTJlviQbK5srodXCsis1z7UYoR-HX4jge5kFBlrbxIAU-czdRF0QmlTqSN2YWzNPt5DTP5s-wYIgsleC18OliS3GVpdp7BDWouWI7CUaBuEMz8a9S_g60qOlo0gxA_XkwEcOJriVU/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;324&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;You will see the authentication status/result as shown below:&amp;nbsp;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyhT6rTSpfkqqBfvOXBO0ILARH96K1Ju_Jze8miiNyCuzvT8XnrSh4wOvI_P-7RfHqK6s1hIpQuHyPaasO2l8k0-sJMlxtSAhOUhZVXLUs9lBz54V-pJrp_B7nAJ5NP-Fb8uatibYVVAg/s1600-h/image%25255B107%25255D.png&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;180&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdX2bQOXN5P3r512A9wCUmMbIHHdYoxnjCleSggBxDl_9fnT3p-G3kP3ztIG6j5_NXbWiaVIvuHKGWs9iXxqUDBUtfzhMFJQtlldFsBPJv-5cK4MdkWTpCAQsBRkuCSEbaiEz-s4cKXss/?imgmax=800&quot; style=&quot;background-attachment: initial; background-clip: initial; background-image: none; background-origin: initial; background-position: initial; background-repeat: initial; background-size: initial; border: 0px solid rgb(204, 204, 204); display: inline; margin: 0px 4px 4px 0px; max-width: 99%; padding: 0px 0px 6px;&quot; title=&quot;image&quot; width=&quot;263&quot; /&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div style=&quot;background-color: white; color: #444444; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px;&quot;&gt;
&lt;strong&gt;Related blogs:&lt;/strong&gt;&lt;/div&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
Configuring Deepnet Security SafeID OATH Token with Microsoft Azure MFA Server&amp;nbsp; -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; target=&quot;_blank&quot; title=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot;&gt;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&lt;/a&gt;&lt;br /&gt;
Azure MFA with pGina and Local Authentication -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot; style=&quot;color: #de2a2a; outline: none;&quot; title=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;blockquote style=&quot;background-color: white; border-left: 3px solid rgb(217, 203, 195); color: #666666; font-family: Georgia, &amp;quot;Times New Roman Times&amp;quot;, serif; font-size: 12px; font-style: italic; overflow: hidden; padding-left: 9px;&quot;&gt;
Azure MFA Server –Authentication Types (Part I) -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;br /&gt;
Azure MFA Server –Authentication Types (Part II) -&amp;nbsp;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; style=&quot;color: #de2a2a; outline: none;&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/blockquote&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2017/10/configuring-yubikey-yubico-oath-token.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDg9aRfj3Tm7gYmkSivDkfb8ZIxBgg4ex66ZORmhGtZ87FxhdwiX6eyLsb26sdHHXFHqshm1AO4nb4BeEEXHrBlGEO7AHvq4q3r3tbuxEeo6Y4ys5gckloz0LKBSlCvJL9DRVBxYRIMAE/s72-c?imgmax=800" height="72" width="72"/><thr:total>29</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-6662477046066612726</guid><pubDate>Tue, 18 Apr 2017 23:26:00 +0000</pubDate><atom:updated>2017-04-18T18:26:11.576-05:00</atom:updated><title>Enable Phone Sign-In–Microsoft Authenticator</title><description>&lt;p&gt;Alex Simons has recently blogged on &amp;quot;&lt;a href=&quot;https://blogs.technet.microsoft.com/enterprisemobility/2017/04/18/no-password-phone-sign-in-for-microsoft-accounts/&quot; target=&quot;_blank&quot;&gt;No password, phone sign in for Microsoft accounts&lt;/a&gt;&amp;quot;. This a great enhancement in Microsoft second factor or &amp;quot;no password&amp;quot; technology.&amp;#160; &lt;/p&gt;  &lt;p&gt;There are a few things you need to consider to complete &amp;quot;phone sign&amp;quot; option.&amp;#160;&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;If you have&amp;#160; Microsoft Authenticator configured for your personal account, you will see an option from the dropdown menu to select &lt;strong&gt;Enable phone sign-in&lt;/strong&gt;. &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLYw8-ypcawfYhQISd84J9T0VUshCdO2rqWDTnRDyg7ZPXlpsrbSY5krJK0rEyKzEXLSFZwzeYpwXy49c5mJNv0wzm5j4dndQVhz6DuZ37H7pMcfyx2UwnvjnucddpXnHwSWfDFKXlCvg/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibD8EecF1yBsaU3UWC6imuarMZl1ut1ce-JaIYgDyTh4RadhluLwWDC1Y3DpT6d7eSolw3IBBHdG12JWNEkKmk-WUX_svafdR3lAmAFcYAjW0JjANIIKW9CjGI7egkFf3CingYhroqSwA/?imgmax=800&quot; width=&quot;570&quot; height=&quot;166&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;But you don&#39;t see this option If you are adding a new Microsoft account on an iPhone.&amp;#160; Microsoft will automatically set it up for you by default.&amp;#160; So add your Microsoft Account and login to a Microsoft service using this account. You will see an additional &amp;quot;password less&amp;quot; (&lt;strong&gt;use the Microsoft Authenticator app instead&lt;/strong&gt;) sign in option as shown below:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI7BNJeiW6uV7DFIcu3OVxuI54ShxJsQtNwn8QdPK96SSzrWwJZXsO5GGXZIIEeITtADs1WESwcWYpR4KQ2X8YE8XoBmUGRPXNVARA6TyrElWBGKEm5x7U0HcoWlSvxtpwxZJqhR96L5A/s1600-h/image%25255B11%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKDHRsycGq5YUQK9im0C4AMc95nrcBvDVHMPG19xXp2XKpv6iWXF_8mN3HjqPaVmlhFfMATAm8DnwPayGG86-woSfcREcW27NvVMXR2QCWMDINFdKQDOF5MsJryANyzo9rOsJlk0sZnpE/?imgmax=800&quot; width=&quot;494&quot; height=&quot;492&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If you don&#39;t configure or add your Microsoft account in your Authenticator App, you don&#39;t see a &amp;quot;&lt;strong&gt;use the Microsoft Authenticator app instead&lt;/strong&gt;&amp;quot; option.&amp;#160; Instead, you will have only see the &lt;strong&gt;password sign-in option&lt;/strong&gt; as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxol2tsbsJ6YZSI-xWDccjvu-OE2qS1W_dBqls2VgwmhVP4ZT541gw9yIIspJNs_Vygh5XYsnAl0uqvJmgkdn-diV6f60qIvncNevyq-F799v_MN19J_aGovCNo_cc8x90B35jUixxSF4/s1600-h/image%25255B7%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5CsY4piJiDXcEw-gN3Ek0CNlAlMOXn-sQrugfh1MqQe5tE_2KmPBkXJhB4EdOeqjkbME1en6ZCT01XEmgOMKp5-jTaPe56ISxEHGZxBHUmQ9th22EO5Mswmlb0q8ss4Ig7-iwTqAwr2M/?imgmax=800&quot; width=&quot;508&quot; height=&quot;462&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;You will see the following verification message on your login screen and on your mobile device. &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXH41ZuWl5R0QvkGzl1Rq4kc5HnV8a87jSrs4jJuroAkt4LKKw8KtpYf_bMRhndGONqCGLvwhsvd7zJGX2lxND2dta6yoXllFCM9XVhQ03v2P2rsYJsZ0QlDCxlLsHViIBAhrbpOOcx1I/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAN5WnvDrpWes2z9GuXpNzip-DdZNufpQ6BDuTkWnZamkFw-RZd_1fTDBJs3_R8hKoQfHapSZJXuhCXE80Xbn_qS_Q4-Aa7tHj2toZZvb1oOWYpXQr8nsgnka4noLp9zuMajxZxhQxx6U/?imgmax=800&quot; width=&quot;484&quot; height=&quot;512&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_shdlYb8iIrRrbyeyzn18miKTfxeks9M0h0W7dhxNduE9nYesoAog7OnFtb-hEdu9d3VTBxDBdSMGK8DSHwqGds-2y7cDlDWSw1yZJSdjDArR5fE2tdkA0zdfL2J2y8UqjFHejouCbTQ/s1600-h/image%25255B19%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8KAfMtDWboaWB08sXqB6SO3tJ6lFee1mwxBzXfqxpp68_LF7sOWRrvgc_IZVi7hmCCMu1AyWUftkh1IXgfaFJemJ5DIjZFedQTVvYpdlBdexX3B4YiPDA9gL2siVhVeCjGKMZQga_XDo/?imgmax=800&quot; width=&quot;401&quot; height=&quot;487&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If you are adding a new account on an Android device , It will be enabled by default and&amp;#160; prompt you to complete it.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjra0vEwjX8XHKf0ZabkhP6dXqJQPIiCUWqRppYZX0iTvD_HeoGe9VPQjLb1YhBYdPIu-90-lC-RglPEcnp-hibG_bynAY5TbQKd7JqYDvmqP8zeC75uexkCB-mcjkzfjsttmUbiOr1eE0/s1600-h/image%25255B23%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCRpGVpNjpEsX7BJMzn1QqGK4v-W9JP2861hqBYCLpkRsAATuPI50QRSzj2d3Zh4JuUmHQlzCsQ6NWG9rC4H_6TNvX5Nl7pyHdt-mm6ElgEVegbiVLcwLRq6kx6putyEtDkaHBV3mTDvI/?imgmax=800&quot; width=&quot;314&quot; height=&quot;488&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2017/04/enable-phone-sign-inmicrosoft.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibD8EecF1yBsaU3UWC6imuarMZl1ut1ce-JaIYgDyTh4RadhluLwWDC1Y3DpT6d7eSolw3IBBHdG12JWNEkKmk-WUX_svafdR3lAmAFcYAjW0JjANIIKW9CjGI7egkFf3CingYhroqSwA/s72-c?imgmax=800" height="72" width="72"/><thr:total>14</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-18548780054559636</guid><pubDate>Fri, 31 Mar 2017 14:51:00 +0000</pubDate><atom:updated>2017-03-31T09:51:30.744-05:00</atom:updated><title>Duplicate Attribute Resiliency - New Identity Synchronization Feature</title><description>&lt;p&gt;I just received an email with a subject of&amp;#160; &amp;quot;&lt;strong&gt;New Identity Synchronization Feature Being Enabled - Duplicate Attribute Resiliency&lt;/strong&gt;&amp;quot;.&amp;#160; Microsoft has provided detailed information in this email.&amp;#160; I thought that was interesting and of course very useful!&amp;#160; Great job Microsoft and looking forward to receiving these types of additional information about upcoming features. &lt;/p&gt;  &lt;p&gt;Here are the details of Duplicate Attribute Resiliency:&lt;/p&gt;  &lt;p&gt;A new feature called Duplicate Attribute Resiliency is being introduced in order to eliminate friction caused by duplicate UserPrincipalName and ProxyAddress conflicts when running one of Microsoft’s synchronization tools. This new feature is being rolled out across all of Azure Active Directory, and will be enabled for your tenant on &lt;em&gt;04/19/2017&lt;/em&gt;. The new behavior that this feature enables is in the cloud portion of the sync pipeline, therefore it is client agnostic and relevant for any Microsoft synchronization product including Azure AD Connect, DirSync and MIM + Connector. Please read on to learn how this change impacts the way Azure Active Directory handles these specific certain types of Identity synchronization errors. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Current behavior&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;If there is an attempt to provision a new object with a UPN or ProxyAddress value that violates this uniqueness constraint, Azure Active Directory blocks that object from being created. Similarly, if an object is updated with a non-unique UPN or ProxyAddress, the update fails. The provisioning attempt or update is retried by the sync client upon each export cycle, and continues to fail until the conflict is resolved. An error report email is generated upon each attempt and an error is logged by the sync client. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;New Behavior - with Duplicate Attribute Resiliency&lt;/strong&gt;&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Instead of completely failing to provision or update an object with a duplicate attribute, Azure Active Directory “quarantines” the duplicate attribute which would violate the uniqueness constraint. &lt;/li&gt;    &lt;li&gt;If this attribute is required for provisioning, like UserPrincipalName, the service assigns a placeholder value. The format of these temporary values is “+&amp;lt;4digitnumber&amp;gt;@.onmicrosoft.com”. &lt;/li&gt;    &lt;li&gt;If the attribute is not required, like a ProxyAddress, Azure Active Directory simply quarantines the conflict attribute and proceeds with the object creation or update. &lt;/li&gt;    &lt;li&gt;Upon quarantining the attribute, information about the conflict is sent in the same error report email used in the old behavior. However, this info only appears in the error report one time, when the quarantine happens, it does not continue to be logged in future emails. Also, since the export for this object has succeeded, the sync client does not log an error and does not retry the create / update operation upon subsequent sync cycles. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;The way all other types of errors are processed remains unchanged, this feature is only relevant for duplicate UserPrincipalName and ProxyAddress conflicts. &lt;/p&gt;  &lt;p&gt;To read more about the behavior change along with identifying and resolving conflicts, please see this article: &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/active-directory-aadconnectsyncservice-duplicate-attribute-resiliency/&quot;&gt;Identity synchronization and duplicate attribute resiliency&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2017/03/duplicate-attribute-resiliency-new.html</link><author>noreply@blogger.com (Blog-5)</author><thr:total>8</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-4325055596806174849</guid><pubDate>Thu, 16 Feb 2017 15:40:00 +0000</pubDate><atom:updated>2017-02-16T09:40:27.960-06:00</atom:updated><title>Azure MFA Server –Authentication Types (Part II)</title><description>&lt;blockquote&gt;   &lt;p&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA–Authentication Type (Part I)&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA–Authentication Type (Part II)&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#ff0000&quot;&gt;Original post - &lt;/font&gt;&lt;/strong&gt;&lt;a title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#ff0000&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#ff0000&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The Microsoft Azure Multi-Factor Authentication (MFA) provides various authentication types when using an on-premises MFA server.&amp;#160; The &lt;strong&gt;Company Settings&lt;/strong&gt; section allows the Multi-Factor Authentication (MFA) administrator to define company wide settings for all users.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ65vouQuoEIpt56rhkvhQjSDBxSCDA4jnLlpYCZnT791iE-yfJxWZNeKmDmS10EOj5EDgEKE_wH4-mj7QILayDfPJMK2YvkOsOUDKsWQIAh5Psf1Vs6pKd94pJY0-ywSQZn09qKHbBm8/s1600-h/image_thumb28%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb28&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb28&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9Teo6e_sY0T2KsvSy87wXKXGgSZpuwkF5Mgq8H9Jl8_VkGN0RnB0qLCwiVcwLq8ZvIyjIxRjTGz6Dp81HpBa3cdlZto9a5vFNRYhRVwhCbOlguIy_W8raFoBzwrVzoLarwx7psuxogpY/?imgmax=800&quot; width=&quot;687&quot; height=&quot;371&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The administrators can also make (or override)&amp;#160; individual user configuration from &lt;strong&gt;User Section&lt;/strong&gt;.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhB3JbV3rGNJPWQSBUs6zbrFrR82B9qLeShlHMPX7ylfpPmPuOZbm93CtS2bGrDO7wZtRQhYfid9s_ArccOTf58ImBG_7ylO9o75oY96w9pbfqyr2HVuoVcU87qTv_7glnLy4rsqxAGWok/s1600-h/image_thumb30%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb30&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb30&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1jtSa5cp7LPtp4d1WfEstLR_2zqvg72A4ZpViZp2GSM2HHn6Hsb_1vB5abMuXO4A4Nh4Prj_dykvAoDacjuIg9SgeNd4s_5K2ZY7M4b04J_cp4xPdAXoryH7l6JSMGHyqO6ye1QDs2B0/?imgmax=800&quot; width=&quot;459&quot; height=&quot;527&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;An end user can make their own sections from the the &lt;strong&gt;User Portal&lt;/strong&gt;. &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTR_-B3R3nUDxS62nwk-nL0Olc8tKpJl13nBbLeh1UA8hZy142RYHrZ3q-qE-Nza98ZpGNKwe9ZkBIpdhKuSZS3NsbdH5GXRiHykEPger1VP3weDBBBYXFdbzLVadp1wRL-AytGMmq5kw/s1600-h/image_thumb33%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb33&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb33&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEguWPlp3hyphenhyphenNEFDTw2YD-qafXYstboBcPNviVBbtNNtYw6oFSm5cIhQFueO686XnEO6mZQp9YU8XADUseKmcsfD0Kw1mSHNdPThXxQWhG5AurUPaohbJC9UVEz3ZJ1N5WE5MJXHhe-3mXes/?imgmax=800&quot; width=&quot;567&quot; height=&quot;410&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In general, the following authentication modes are available when using an on-premises MFA server. The purpose of this blog is to explain each of these authentication types and expected result with screenshots.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Phone call (Standard) &lt;/li&gt;    &lt;li&gt;Phone call (PIN) &lt;/li&gt;    &lt;li&gt;Text message (One-way OTP) &lt;/li&gt;    &lt;li&gt;Text message (Two-way OTP) &lt;/li&gt;    &lt;li&gt;Text message (One-way OTP + PIN) &lt;/li&gt;    &lt;li&gt;Text message (Two-way OTP + PIN) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (Standard) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (PIN) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (OATH token) &lt;/li&gt;    &lt;li&gt;Third Party OATH token &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;In this blog, I will be covering the following authentication types.&amp;#160; &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Azure Authenticator application (Standard) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (PIN) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (OATH token) &lt;/li&gt;    &lt;li&gt;Third Party OATH token &lt;!--EndFragment--&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;Review Part I of this blog for other authentication type details.&amp;#160; &lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;The Azure Mobile App mode results in a notification being sent to the user&#39;s Azure Authenticator mobile app.&amp;#160; There are 2 different modes for Mobile App – Standard and PIN mode.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure Authenticator application&amp;#160; -Standard &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for primary authentication using a user name and password and the second authentication is when the user receives a notification in the Azure Authenticator mobile app. &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVpHnn2bGZmLrf8_wOxf8FbJan69eNHbmKYBN0xCBU7gEUyoj1Egs8p0-j8eC574yyBz3TUfgvFYLkx3dSRRDp5338yQdrrx11vIhVmO6BspYpeZFfPysmpgp03UgTTs4dW5zsDJvZTfc/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9GULSj2jfwKIZaxbudnX3oivD7GSc_srg11Aq_L1WbFA-Xvmo1PW507VMK6VIxxgTWpFtwUHlyUHDY3kqwBLUhcNOiZVifJGhDarGJvSEBPzK8Z2OiuzSt2Q_SOPtjXP6ZuJ8iaRgfRI/?imgmax=800&quot; width=&quot;365&quot; height=&quot;119&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In Standard Mode, users will prompted to authenticate, deny, or deny and report fraud as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6C3z3ciac406nbxbJU4WGMGR4ClRXPpIt1vrKn3hz-BSNTxV8P3v_LmLZijmX8FpVqie0XniX0Z8WaaZRwRpuuL7Pcp2PmlGpM5q7uZ1_UZoQg8VfKU_M4DE4AelfdqXuWfywqLbysx0/s1600-h/image%25255B7%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxd09LtM0t8K978RewV1nVnWvg3q43qVwPBn5daJ-4kqd297MKt_QHNo5xXzIg0wMuNPD164UUTWe7n3kJtP9nAudyFm5Rgrrv63OkuKZ0qepZlF4BGt-M1xRFdu0U1bwfAsHHEQxhrp4/?imgmax=800&quot; width=&quot;411&quot; height=&quot;527&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure Authenticator application – PIN &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The PIN mode enhances the security of the Multi-Factor Authentication by requiring the user enter a PIN in the Azure Authenticator mobile app.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPkxqp1KHYCsW73Vyw7RwdY5C63WR53y8PlXAISnaTX4bLacfyYnBhEkQg67xS9f0yG-x3xQSua4tKBd67ONpYXn1_e3BIh1ubgl38_pR5d7i5ISLh36fjhMZPJI7yuDwOK9OjwWZnfHQ/s1600-h/image%25255B11%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaGCGoVLFtlvqo89KUN_iaKmxMjDk-BMl14cmoBo_SUQP8lkqxUWkGmnojrMckKzIQeaXX2qAZ9YIlC4f9Y1nvj6VhpbnyfC8oeQtC0DwU3T4LVUUMR5NIED5UYTNO3uwHHGXAp0CB0Z0/?imgmax=800&quot; width=&quot;523&quot; height=&quot;244&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for primary authentication using a user name and password and the second authentication is when the user receives a notification in the Azure Authenticator mobile app to enter the PIN number as shown below:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2s5y9lYg1OGAHso-xm0kfDpKeANdNFVJogs2F9OLynD07xLcNESvSdlTFmj9VH2qmOuNaPL3sM3buxO2zCl10U5YGWJ5T57FaC_Ia0I1YnZBcKFKIDHhtZNvQMg0aqD9O5oa1ZZSndd8/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIrYcnFs8z1PcMX0j4wQaUHmFJ7nLL2dnswkSO_2RmYmq-_XWirocIYxWMChwyYpn0hyyuKkN9s53pJ6dDMiAvZM9sLf2pv6YRNSbB35XMxOiQIjPiqIHYqYvFiTV1QeinP8zjdrSgidk/?imgmax=800&quot; width=&quot;243&quot; height=&quot;419&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure Authenticator application - OATH token&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Oath Token mode results in the user being prompted for an OATH code to authenticate with Multi-Factor Authentication.&amp;#160; Time-based OATH codes can be generated by the Azure Authenticator Mobile App or a third-party token. We will start with Azure Authenticator Mobile App. As shown in the following screenshot, the OATH Tokens (&lt;strong&gt;Enable OATH Tokens&lt;/strong&gt;) must be enabled in the MFA Server console to display a Time-based OATH codes in Azure Authenticator Mobile App.&amp;#160; keep in mind that the OATH Token method is only supported by &lt;strong&gt;RADIUS Authentication&lt;/strong&gt; and &lt;strong&gt;IIS Authentication Form-Based Authentication&lt;/strong&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhodl4uS7LeiqBdUv9xsINfVmy1PYKd-8NRkycXVTp7-d8bgMbkeE1wON9Pnj1Z7O91gPFq92_lVNISx8rGAkOi3g5Lq7yWhCKMeegX_DzMh-ezFaRhP0TfCWnmIsf6mF8FbBKQwlIX2rA/s1600-h/image%25255B53%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjd0wHCOXDqWCcJOlhFK7vUMBi30VQA07y0wiRWmRI9gQE0Ue0E7EpWL6Jk3WxUVm111ehvpwuUNbjbbSqlGPx0zAxRMt-HTTAYhvYwXEyzvdrcjYH4WO1-v3XmJ0vNrd9Hj7kG6xR3nc8/?imgmax=800&quot; width=&quot;849&quot; height=&quot;441&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;After the activation of Mobile App, users can select OATH token mode from the User Portal or an administrator can configure this from a MFA server console.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg90W20Lp6M3Zvx0eNi14cbMHXGIzvoIJ-1ZHXVfxGZOxHQ7xa3IxOBzNNVcNjo-H0_HJeWWmBZor8ly9AHFeplPO8Ti1Z32z3NmcXK22l8KootUX2-7oL7wIDtKDQkPEpL99cyucqJ8Zw/s1600-h/image%25255B19%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjYk1yw9EA7WjQt-Ow0rpZHS5PY3BqJlvR1lQbOeB5MZ1l0k5ff9KZTMjollucRRNIS_jA-NJZAnNU-C9jeBInduSztF2k5cTFe-DSeYu9ETHS0WUM_dQJvUEEvFzPLXphHIHVJ13m-jBg/?imgmax=800&quot; width=&quot;363&quot; height=&quot;167&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;A Time-based OATH codes will be generated by Azure Authenticator Mobile App as shown below.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhm5XzUeoeWh2lCG_4CMJ6U1TxQS_77Kg55virt1WdojTfv9RxAIjhMaIuhxs2XynhncKOIZEu2sZ49s47PHXC6sCG_oDuShBW4t4Il2WOfR7EugM3GfLuiM7r7TuK-PauvtFm3bih-TJw/s1600-h/image%25255B26%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhH1xlhMyiSO46VgxPDWybJS38xYSXcJkG8Q8z8c3AO7EmBKB_24U82cneqHsHNUnk-Unbcu-BCiW6CiycQ2YEpOYhO-iOAnQ-1tcYbXzP96N7DW4UJiOLHjJqIoozQRllM77fTtJedVxo/?imgmax=800&quot; width=&quot;242&quot; height=&quot;178&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This code needs to entered in the respective application to complete the second factor authentication.&amp;#160; &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbQ3m-xhb3ecIJU9bvgEQZ3KZjquUndGxoBCxvx2Vks0g-g3UiqeLTAstTX87czv4Ub2OdySkp8kY3B7TWjeNN7VOVn0c2brDKYlEMKxaym9gWMyjdD5-j4qotCpYIAZDxooofJOlyIPY/s1600-h/image%25255B57%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3A5aofelEcxRPzQnlmX9jq5ZE54RsME8f4tesjKaV0Km5jlKfe1m6QaDYoFPMBV0vF-3qsTPRZEfeHSTMm7kjSfzvSIBuSofvMY8SluAspvDX9qcI48yPmbh2W-Xefk-PGnirjRHvX6g/?imgmax=800&quot; width=&quot;315&quot; height=&quot;139&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Third Party OATH token &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Azure MFA server supports a time based OATH (OATH – TOTP) third party tokens.&amp;#160; This is an alternative to using the Azure Authenticator mobile app as an OATH token (see the above scenario - &lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure Authenticator application&amp;#160; -Standard)&lt;/font&gt;&lt;/strong&gt;.&amp;#160; OATH tokens can be added or imported prior to being associated with a user.&amp;#160; Administrators can associate users and tokens in the Multi-Factor Authentication Server&amp;#160; (as shown below) or the User Portal.&amp;#160; Users can associate themselves with an OATH token during User Portal enrollment or using the OATH Token menu option when the User Portal is configured to provide this functionality.&amp;#160;&amp;#160;&amp;#160; A bulk token import and configuration is also supported by MFA Server .&amp;#160; An administrator can import OATH Token records from an input&amp;#160; file .&amp;#160; The secret keys must be in &lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot; target=&quot;_blank&quot;&gt;Base32 format&lt;/a&gt;.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMkeESICbpfMZWPz3AXAmRLKd6lCCtmVDt58FVAU38sDvu2J3s-nyzGM8owiPr5CbNvkbttiLi-955UvCHhDrHjmy8dvVvTaaoNK4aj8o0gB2jAfPReMyLxh6Ogv3fKppL4dOOwUM42Og/s1600-h/image%25255B49%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhW0LnhMgMoJRBop1BIeSgaTbqVOcGOMmRWTvpUar8jk67lmTjzWAYsNws_EiJQuQowCwjir1opYqL4fcTIf-0rLsw2uQ_YWLJdplJLA2oa4wWvXO9NBujYtxVTiD_u9eePHqwhk7Og3vY/?imgmax=800&quot; width=&quot;896&quot; height=&quot;219&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;For this scenario, I am using &lt;a href=&quot;https://www.yubico.com/products/yubikey-hardware/&quot; target=&quot;_blank&quot;&gt;Yubikey 4 (Yukico) OATH token&lt;/a&gt; as the third party OATH token.&amp;#160; You need to use &lt;a href=&quot;https://www.yubico.com/support/downloads/&quot; target=&quot;_blank&quot;&gt;Yubico Authentication application&lt;/a&gt; to get the OATH code from Yukikey.&amp;#160; Review my &lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot; target=&quot;_blank&quot;&gt;Azure MFA and Yubico OATH configuration&lt;/a&gt;&lt;/strong&gt; blog for the configuration details.&amp;#160; &lt;/p&gt;  &lt;p&gt;The OATH token option is same as the Azure Authenticator mobile app configuration as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjndEOpu3aYNiAq4B4tUg3CUTTqTruemZfNpujb9yjcTVrzQtAxnmmi-3S3_PeqJH-008KuJrazgBwIElVrR011H-ci5DoF68yj7_mkKUCmw7_ebSrzQdph-umPjyx711fkZcqFX-UbFqs/s1600-h/image%25255B38%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXUIW0_WEEtK1MuZYrum1KjVbFbp0TSXQLOdQtZjXUgZBZmSO2Jh4Kx4VpwXWppt4j9ddrGM8DZaw4kj6qqcQIFuA3wdpD4SiL3LKEcavomLK9CrEBTKnLevhg_Dm8h63tZRrUKUs0nBI/?imgmax=800&quot; width=&quot;545&quot; height=&quot;218&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this scenario, you will be using the Time-based OATH codes generated by &lt;strong&gt;&lt;a href=&quot;https://www.yubico.com/support/downloads/&quot; target=&quot;_blank&quot;&gt;Yubico Authenticator&lt;/a&gt;&lt;/strong&gt; application.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgfCIrb3YR44CdbPiHraZkifhBssqGlJCJK34zoAfh_GsPaoc0vZPtW37ikMCSRimQiCN8Krd3oeQaTuqGIviP7xV4KprKCX3pMMjfDD0n9P5PIMQsmRs72y000mUJpL_kIhSDVRvuGpc/s1600-h/image%25255B34%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBveQ9UnokLoykbfBwZpsTYT8YgrPAZPzYt8lfGz9lbieyIPGgDMENp7D5wyodGZ-7LatwbtWn4vFY1O3pdoI7n67hC4beCVk36-FSX9pinkxC7K1mXNQQpHC0nZ20TABqFFn96IIbp2s/?imgmax=800&quot; width=&quot;346&quot; height=&quot;141&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This OATH code must be entered in the respective application to complete the second factor authentication.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuv4XWZg1lSgjQhJHzQubyGvBo1Q6fsnTYBUvhoff0-lcl7JHfwxmzbE2tqcVFnQg0ZWEOFVOzmL5DxOWdQJXwZkKZTrfot60mgA0kdxPKU0pvkbHCUrNGhzSy15iRj9zn132-7mycCXs/s1600-h/image%25255B45%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtPf_OV48M7QgyyGKxUQofCp46HXN_z8EYOsOTPqRRCWuvNfEdV56HlOmVbeiNuygLX6XuZKHGFj4vwssoCWQIfI5B_u4iHQbyzLhJDuyWl6bdChJtLPywaEP3lGQ_5uCAH3YEDBlUtgM/?imgmax=800&quot; width=&quot;313&quot; height=&quot;137&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If you have Azure Mobile App OATH and a third party OATH token active for the same user, both token code will be valid.&amp;#160; &lt;/p&gt;  &lt;ol&gt;&lt;/ol&gt;  &lt;ol&gt;&lt;/ol&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA–Authentication Type (Part I)&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA–Authentication Type (Part II)&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/06/azure-mfa-server-authentication-type.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9Teo6e_sY0T2KsvSy87wXKXGgSZpuwkF5Mgq8H9Jl8_VkGN0RnB0qLCwiVcwLq8ZvIyjIxRjTGz6Dp81HpBa3cdlZto9a5vFNRYhRVwhCbOlguIy_W8raFoBzwrVzoLarwx7psuxogpY/s72-c?imgmax=800" height="72" width="72"/><thr:total>15</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-771751865701520058</guid><pubDate>Thu, 16 Feb 2017 15:39:00 +0000</pubDate><atom:updated>2017-02-16T09:40:03.167-06:00</atom:updated><title>Azure MFA Server–Authentication Types (Part I)</title><description>&lt;blockquote&gt;   &lt;p&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Type (Part I)&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Type (Part II)&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#ff0000&quot;&gt;Original post - &lt;/font&gt;&lt;/strong&gt;&lt;a title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#ff0000&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;&lt;strong&gt;&lt;font color=&quot;#ff0000&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/font&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The Microsoft Azure Multi-Factor Authentication (MFA) provides various authentication types when using an on-premises MFA server.&amp;#160; The &lt;strong&gt;Company Settings&lt;/strong&gt; section allows the Multi-Factor Authentication (MFA) administrator to define company wide settings for all users.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7dDupjupLk7M8lZnEG71sh8L-_gKIKik3CpjeJXNvzUgB25AHTvvYS-A9A6N_DfWIxer8y_FMNg2dys603ZmmVgdxici4Ua_821F6cbODmEPJ8bkfKYbPUwTxIGTzjLvmzTJLu5EP_Cg/s1600-h/image%25255B64%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgxnYxlHOPiEy__QZX0at1V19OwnV_EzBPT5V_bQqqu3qOlnhLNuYqxqvOKphyphenhyphenaqqoyLPVlFDON-RIGiQ1yRKKhpfVGG8vVzjc9XhYSq4MmUUg49TYcsJEKgsrQQmjIyVdRT-UcCYHuRw/?imgmax=800&quot; width=&quot;687&quot; height=&quot;371&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The administrators can also make (or override)&amp;#160; individual user configuration from &lt;strong&gt;User Section&lt;/strong&gt;.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9gZ-T3vC9MgzUFk6KBLxcHVvCKfhvSqBa12RKhLPgnIqeCQHNu__c2ZHDVOIjsiDtCH8aOXQRp1e7vQRPISl4S6349KYY21Msc7geP6X9R6eNk0bjfcG792NTRtACnZ23KhmZu1jMshI/s1600-h/image%25255B68%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEge4VhH3IqJQZcjSUBz3jklo7GmQMwyGV1GYGKT8H9ylehiyals-EASpStm-mC4RtKphhpcfgPxzLu7g_DU9PdEfUDrlYnmt2b777lCxnr99uUqf-a32e2D5M39kX7oIewhw5Pa5axguQU/?imgmax=800&quot; width=&quot;459&quot; height=&quot;527&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;An end user can make their own sections from the the &lt;strong&gt;User Portal&lt;/strong&gt;. &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3yHaYfSTbygYmEhTvQxHhs-5GhGPd96zqvFFrxhCR1d4CB1NtJpbdDAQBS0BPU0rPnr4NKWAkmQiJyTtOFFLX9NPPv9slqSuoaMUqCOhdw_xg4uvC8TTj9ZmyF6jGL789Id40deP6ByI/s1600-h/image%25255B75%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiW5IHj9zeHhlWVAmsr19IRg6KBCxP0jVLt03ip9alxMWwouTtDqc25kp3WhTnfw_Nv-s4Z-VAav7imhkJwCWyU07SaSF7FVJ0VUiv415TNFEwDMWNExcFnOaHeXBuI3eoqM2aiX3ZjjnU/?imgmax=800&quot; width=&quot;567&quot; height=&quot;410&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;In general, the following authentication modes are available when using an on-premises MFA server. The purpose of this blog is to explain each of these authentication types and expected result with screenshots.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Phone call (Standard) &lt;/li&gt;    &lt;li&gt;Phone call (PIN) &lt;/li&gt;    &lt;li&gt;Text message (One-way OTP) &lt;/li&gt;    &lt;li&gt;Text message (Two-way OTP) &lt;/li&gt;    &lt;li&gt;Text message (One-way OTP + PIN) &lt;/li&gt;    &lt;li&gt;Text message (Two-way OTP + PIN) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (Standard) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (PIN) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (OATH token) &lt;/li&gt;    &lt;li&gt;Third Party OATH token &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;We will start with standard Phone Call option.&amp;#160; The Phone call authentication type has two sub options: &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Phone call (Standard) &lt;/li&gt;    &lt;li&gt;Phone call (PIN) &lt;!--EndFragment--&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Authentication Type : Phone Call – Standard&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7lCtQH-qAy0Asm46YOTOEiPuoqGDUiIMczoomvnZv3sRHwEMN-QAMpPAXGrpFKozwgB6On3zRymo7oMVXyuGTIzKuve_tuISnmCkVUh8j6x2rZKB2M3cmHzHXo5F5bZeYBghhsnnbP9c/s1600-h/image43.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh935ogfj9PgddYMI-iD1GwciNuHGVoXTWD0mq07yqppZI_pBd7Bs87ODuVZ8GFuLaj759d8XHNPrasxr-rjPnGEIJRxd8Vsg3KgubJiYrP46DdNDkvMsBYHiJRXXpyrCW2nZw5Rj5ye44/?imgmax=800&quot; width=&quot;339&quot; height=&quot;235&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for first authentication using a user name and password and then the second authentication is based on the phone call as shown below:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNwoYOID9jlTm1eX2t8gLYWQt-U66wjdumSJmFYzWRhbeSEbgTc3sSb0m3jU9lFxc65AktzUyGv2AOM4s4wYxMDlyCohpgG-jEqMyi8S__3jzX5MtuvxItPX1db9nre2TvsGF9s5rTlSk/s1600-h/image48.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJNjv_LUbAm6k89ECQZwnqvPDmfAawTGJHIRKfRqHshyGFNZ20A-MzUZcP0axoLAV5hFFARNU8DRa1Eqif6IN1ZdQTR0Lwyzj6_k49aQEe612CXnwERmzJAT5tm8UfRxuoX3V7r8hA3Zw/?imgmax=800&quot; width=&quot;141&quot; height=&quot;250&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The first authentication is based on the configuration in MFA.&amp;#160; For example, for RADIUS, you an select&amp;#160; the following options from the &lt;strong&gt;Target&lt;/strong&gt; tab:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyV75qHgmxiesdOxOUzYm87FoRPB2qhmTv5wRs0oT7rZOmPlukLWWPWeITGdfsqf-EAU6IUwwvbLqneOUE06hQ6o7ulIkyZ3kM3U0K7GV7JXzVb-r05twLpeZufb-C49VtrL86x-HRLZ0/s1600-h/image%25255B33%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEheeI20Y6VgzLu5HaWeUI0XA2AtN3RCojgUk6W8K6uoLfqZJ-UTU-aI0l9I-hwqILQXd_F31KomjYYpNj8-YBUdnRBwSdFHRvxUzAELMRcSdYkDWpPomHjz5RrgFr-GNQ3RtY_NGgioHk4/?imgmax=800&quot; width=&quot;684&quot; height=&quot;349&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The “from” telephone number can be customized from azure console (&lt;a href=&quot;https://manage.windowsazure.com/&quot;&gt;&lt;strong&gt;https://manage.windowsazure.com/&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; –&amp;gt; Active Directory –&amp;gt; Configure –&amp;gt;Multi-factor Authentication –&amp;gt; Manage Service Settings –&amp;gt;&amp;#160; Go to the Portal –&amp;gt; Configure –&amp;gt; Settings –&amp;gt; General Settings –&amp;gt; Caller ID Phone Number&lt;/strong&gt;) as shown below:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjI_DqTsit8zTW8DCUpAJ4Ev00a50dsUfXAbxhpINtoVOUP1Fgy2Ax1Vv9rQm9NnQRgGrJqw0U4SCH93KbLvtveD9pWmG7h9-ijHONFsk0lxZeRp7T-iVZaQ47CskIAIPqK5-uK4u1nNng/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgsdOg8DAGZpCnK1D4RcfRyxFRDVIQkiLJP-t5mL9agJpftu5I6x1qYrvnJ32aDnSRXJcjY-lDSnsvnEq8YllAw4Af0UjA3DYowXT_emg1DqoL7b9D0BLRs8iQ4roxiRzXWuDCFHePYmY/?imgmax=800&quot; width=&quot;1006&quot; height=&quot;649&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Also, the Voice Messages can be customized based on your requirements. This option is available in &lt;a href=&quot;https://manage.windowsazure.com/&quot;&gt;&lt;strong&gt;https://manage.windowsazure.com/&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; –&amp;gt; Active Directory –&amp;gt; Configure –&amp;gt;Multi-factor Authentication –&amp;gt; Manage Service Settings –&amp;gt;&amp;#160; Go to the Portal –&amp;gt; Configure –&amp;gt; Voice Message &lt;/strong&gt;section.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiwsBDM2jHAGztShfsOKyXGn8IIHAXhRMUnqGf6JW8Q-jpoqjQJ4RBYWdKXgPsBAxjNxTo4gY8v0FV7h-nlifnrcHA85ISiyvtr72kfW3ecWWIYr5bfVnG3thIro45U6WtanWatw9X-8CI/s1600-h/image%25255B4%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVbB1KyzrjbF2whtSLYCQ_mfE_UN7J5wm9KaSEHdHZJj5YbjXpovojGDKDoDxOBvu7huIIzAu-WUGEemuE0Xt-3CuWHe-LM68kVSZU1gq9vgRJsSR95GHURuy7SQ2b-ka0cYrA-IER8p0/?imgmax=800&quot; width=&quot;960&quot; height=&quot;580&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Authentication Type : Phone Call – PIN&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this scenario, we will use Phone call with PIN option.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx-bOESA-NsKPEMFz3OaIrhxV1oQYm4Rqp0mHZIQ4ZiEr-pgYB0fRIcFggmZC1FwswF91DwiX1-5dhKf5d-sWyxVH6Zu6W1nVUJYP3hjAS_NODexvQk1hcD8bpWVn2HmrLhaWKn3kpDCE/s1600-h/image52.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAMwaUR7cgoWWaw4SC7lvWmCSX8ZDjOtcwg8YPNuwbHXZAc0g2FWo1dQpyj49nv3mu4t3SJA_r5zyierLoeIOszpsQecLAZdKgbzWWI55KWdNLXHYkrSza6syxhWrLhe7SiNaVnqaq8Sg/?imgmax=800&quot; width=&quot;342&quot; height=&quot;237&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for first authentication using a user name and password and then the second authentication is based on the phone.&amp;#160; During the phone call, MFA will ask you to enter a personalized PIN.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4jkFibombj6LUdOR86xn1wKx-6ALHd4obRWWTUIdZXuqkHmNGTnYaCCjdVZ_EEPhVwGAEO9jOr7Ec1an79z35WEVsMTUc0_7ERWsgakcdpQnkGsVWiLLFlMglyKEyWw5VSQRLciFtBzQ/s1600-h/image56.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxsuruNQKsjzIlv05uQroOBuswiAv6X77zsJ9ePBHxTpgeqU5GxB8s0K6EbD8rpUn-uRb7Qpbmcnt23RWg_IaF8hyphenhyphenaBQJnBKu1H0AAMY2mo-6L3Ra0M1Hio4h2EKmkWzygZLApRQj9HMI/?imgmax=800&quot; width=&quot;141&quot; height=&quot;244&quot; /&gt;&lt;/a&gt; + &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVwOHSuUiLjS4zoq33k2yRLyzLmWMwlJeqMJD9HhnwAXg77mFRK8MVcR-GyCtOxdyXpDQ0voI8osx4ISL72n2f-5op8__N2kPFaPHbFPQTDkcSE1dAhjH4wd0U4SIJGEX0W16WPqvF_l4/s1600-h/image%25255B6%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6PZ30j40B0INkIUidjbaQ6E4EFsBg6Ja0fx4Tj72cGqNsnlMOxgP9AKVTAZYZHJZnGJkl5KtEJk1EB20NueyYaGcGnTKcn4k5fNSyN7QQ4ZxX1dpwHBZqkw0uYh9J3F7V0cWUNHWBYIU/?imgmax=800&quot; width=&quot;141&quot; height=&quot;244&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The PIN creation and enforcement is based on the following configuration in user section.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3hs2cofOXgYVXPodit3OopQEZmvuutScvCwLNDnaqxADRECZAoRGNrCJwonx8GIThxvZTeBYKJ3Bo5un6nw8QcZLgQozW1KJQawgzU9ABJXTQpSFVB7JnGIOmWKEByIFBEtHZjpY-zis/s1600-h/image%25255B10%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgldb3Tx7pjXP6DjoLN2XI17rnju62ivna2V40HC5e6YuA3vC6N0ejycI2pFitSG-EVInMq5qAgysDzbFzoZlxtzMcXriUA75N-_XIqIvNGROL-ZRPJbHBL8dR0ARhGTUxm9g8iMXUYJrc/?imgmax=800&quot; width=&quot;569&quot; height=&quot;242&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;You also have an option in Company Settings section to enforce default PIN rules as shown below:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaSoX6VrZOLzd_3JPt4BFi7wYTTXUXkE3S19BU6uid5D7CJtiQmqrS6Yt7J2HJa7OVcMALu7jCz3Vlq68tpFS-SQhkYb-CNfXR7tbjOTINu-aHSE3M9ZAb8q5nRQEKbjTVSgc_dAXTew8/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo___yqj3EFoeOmrDA_8JR7tFQTKaKTIuTimXoYAwJBREyLJ_PWYOXtSyilS_btSI0qx5uaw4E48XhLwVfSPnojGGrFp3Oa9X2wvp3xrv_5LUJ63r-8fR7SI0EEFz5mP2klG5FjcWg3SE/?imgmax=800&quot; width=&quot;865&quot; height=&quot;348&quot; /&gt;&lt;/a&gt;The next authentication type is Text message.&amp;#160; Text Message type has four sub options:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Text message (One-way OTP) &lt;/li&gt;    &lt;li&gt;Text message (Two-way OTP) &lt;/li&gt;    &lt;li&gt;Text message (One-way OTP + PIN) &lt;/li&gt;    &lt;li&gt;Text message (Two-way OTP + PIN) &lt;!--EndFragment--&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Authentication Type : Text message - One-way OTP&lt;/font&gt; &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF8t07SS9x1AsbQnKszvDmG6dOwecXcGAkiOSfWjm5gjs8F4ikBqKNaeGqMfIG4JI0tIL1cROccmLe4NB4MMBMAw-QASlN6i_a9DWoLCfMH6CPS3z8ZCGqtOc8IEYTfijiNp3UouIrLv0/s1600-h/image60.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6iF6t09uEOLUzKwvdWPHlrybmy-uRuzJCoTgp_K3ae7O7VV7zgH_EsJ8T3kt8j8cK4Kzh6YJV3iKlrcH19Sj6Fe24YfMD98dBmu94iRBagXgAWjDVBvAmKNpygLMIBovBwo3C68Nj3Xw/?imgmax=800&quot; width=&quot;881&quot; height=&quot;312&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for first authentication using a user name and password and then the second authentication is based on&amp;#160; a text message containing a One-Time Passcode (OTP) is sent to the user as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgROQ3yRX0Ivd-r4clwQxqyYQ-cNT_DtOn9yomt934HRDXxKlBPm8VfUSWT8bQMdsgylPCKZrJJumvJVN5HYsbyqmhc7l-f9OfXT4cGmSaxwqNKM2nE5RuYUqJqhlSCwdHxmTphJRA2OQY/s1600-h/image%25255B21%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_pl-RU07WXyrtGY2xeKwsElcGTM-38bYe64dyzWRfyc_xwG007zJpQN3bvLmGUr2PdNkzASlEghyphenhyphenZL07RLjXOvo3ir3Z5_79URhgvl4ghhdQaCmmy4Wc7q0y3YSRFv-DUV9XbBNPI3jg/?imgmax=800&quot; width=&quot;244&quot; height=&quot;186&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The user must enter this&amp;#160; One-Time Passcode (OTP) in the respective application to complete the authentication request.&amp;#160;&amp;#160; You application must support Challenge – Response (Authentication Chaining).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA-WAIebZYoauhA15hkOupQCCdye5EEe0fQY43vPy0hLLuXMRTP6GXRcpQ45EAtGcJ22CgycKCN06xb-GblyMaTTAIXAB6pQ0qGY1GdjIdTMzTWE4jQve4eg5dQcx-F61Bhm_yZka4XYM/s1600-h/image%25255B22%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiEUJYGltMbLNFh6sQCoq-dZg6GNDm4ZGmaUm8vlyTzMdUUGuxP8oKdouwTdt3RPP7X71-TiLafV33IQWHCYPNdmnMQ32k5A-_2wrvTSBpvLsA-egPtoP6XAA7jb7uqPyvmrD4pcz4la4Y/?imgmax=800&quot; width=&quot;393&quot; height=&quot;139&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Authentication Type : Text message – Two-way OTP&lt;/font&gt; &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuDAJo6LSuabyVJA4kSW0n1WNX0q0i_YTpT3AL_tJcXHqndIU1inHJfg9DTAyyBOJa_CWXCbGFCzj3LJLB9lXfNGMpvrrFWtoCBJGrPRTo229bDuVXTkgB6ilLmIxUz9nstBg0ES3zDhM/s1600-h/image%25255B26%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4mfiYcbsgxY2z1jtNTZ7XH_gXG38ULEQ5hnHX1V_5IiBUPYEyG81q-HwDbutZ3-fB5N8bm-lI0nsMj2RRk_63tJJ_MogtF3O24XPrtC45crR0DL1sTyZY6Q4FiHVHmOOIPiW7rqxRIf8/?imgmax=800&quot; width=&quot;526&quot; height=&quot;107&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for first authentication using a user name and password and then the second authentication is based on&amp;#160; a text message containing a One-Time Passcode (OTP).&amp;#160;&amp;#160; The user must reply to the same&amp;#160; text message by entering the provided OTP to complete the authentication request as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLK_szbjwhgnKy3Nt_FyU0Yy5hPsYsAUTXZtxsX3BaJzgkyFPkIwJwaSUCtpALWqfX1Xbi2dBMfgosxZf06RQAhhqiWDnbRsvldSZp-YUAZRUHAOM7e1-4yYHiwWeo9x9XR5hzugFQowI/s1600-h/image%25255B29%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIiDWDvzH1qZbkpeO_RyUxWNib4W75pkQtuY9wNyN8THUhBTPRdmdMk72X5HWLzbzT9HjRK5h4B3a7aqqiZRjKQ9NhHrcSQd9T0wLm5s6HfsdHyyyV6_on40h_-aiIbVvnOVs7A6i30W0/?imgmax=800&quot; width=&quot;236&quot; height=&quot;244&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Authentication Type : Text message - One-way OTP&amp;#160; + PIN&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4ADlUysLkLKko9dOgroBE4V9IP7WJS8aL9JP3SiutieSd-sDFcdn0bY0rYwuGf5ZuUoDtWoBF7wqtgRyoVpIawJceVhIuLBqkSN8Y5q7l9GbhSDFeIOO_AoYvpmEgtcK3-2K2jB2_myY/s1600-h/image%25255B37%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj7D6H94VUhgecsBnShrynzSHuYpciPOHykrqcqGBIielNGwFiwaAJE4yd-Ea9V6WxY2b0mwQZhLTu6Cgqkqxks9rrxZfV3ied5wlKYK3woQuLyoth-JZ1b6RhOk03GsuuxbWOmJ173IQ/?imgmax=800&quot; width=&quot;551&quot; height=&quot;182&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for first authentication using a user name and password and then the second authentication is based on&amp;#160; a text message containing a One-Time Passcode (OTP) is sent to the user as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTbbr7d1U_RvZttS9vQq3S-IuyzsMSGxjedrMkYKW24YrFN_4Up8vUprVHt61dUNYE6s0eGQ7OpoYixpSXraCYWCzCh3lFRsBq6zciawV57grMFq_ks85cDKbXwsRd4qYf4-ZMYvbk_dE/s1600-h/image%25255B41%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGh_4oRYL6TNxU_38crYfq2vfliDXMjmroodd6vhyphenhyphenDajLUw_35AoUSKzsigWQtpYVtqwiGmLlqzD-_cMVfYbTQHYJ1ZYPZxg-8rgwiXIVqWSR6DcE_UI7S4CMnlplyNDO5tpSar1qKIqQ/?imgmax=800&quot; width=&quot;244&quot; height=&quot;186&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This One-Time Passcode (OTP) + PIN needs to be entered in the application to complete the authentication request.&amp;#160;&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiR74WvaEq_p-nvDPLjZz-o6xzqeFJS2xBWWOH7oFseC1ZE48689_igbarpmP2PSBu3KSOXYqGwBolXL-ZFxTnwyzbIEq88WpbxxuOYVfQcy6aIx8-kG1fPs_ppyjaga_jP235UPMVscYg/s1600-h/image%25255B44%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSu-53XfbOv_j-acoqM-kr90ABLbqjhTn2TGubFBF_a4DsW5wFIotU2GfOj-AuN5yz5qO9Vsfu5-sls_CNrkUYQtul_T8uRYojglRSAInWNU0u1QZHdBuZqHDrkUjq4ZeV1x1kzbkPmWQ/?imgmax=800&quot; width=&quot;244&quot; height=&quot;88&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The PIN values is based on the configuration in the user or Company Settings:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;User settings:&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoyFq7nuIbKoIiuS_Ypvh5JHS0zr2mQF_-9H5gKEOcMOaZ9ytdU29qP45z03FgftF2HxZPZZQMrvfrUY7_eyqobUqbKxsgA81krp7mLK9qTH9zSJ6ltzG5rlVvvwltAq-3fX8EIl9vnAY/s1600-h/image%25255B48%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmkKzntaDCkE2GZSR11e6TKTgyFTPI2B-AZIqiKZYmlH98J4gwUQpsFFbetx00ZfUaZdZCUvPosHEqSvVSL6Y-y9prZSDlL-iBzAjLl3WaSQptMmEs0UWp1mEwBAAQAEPrN2hp56BapRE/?imgmax=800&quot; width=&quot;552&quot; height=&quot;232&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Company Settings:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj7r4nFMi07OD5WR_blZcj6yrO_mEtj4oy6v-t75SCKJNNFMOY31TDi6XXGUM_ovUFzyVljqgPRXB00Z6D87bSndvH2zOvcoHjLuzKscx3vv1MKIfKrfNHwj_zOURRYFTE8VykC9IqVJM/s1600-h/image%25255B52%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8JVtb0UxTpSnCYb_hGqeaXPlQI3BYi7rXEAJURTY2DSUiab43gNSSfthPpn4MiMM5MXRTBz3jzEUfN6V8-YCmG9PMXESrLmV9oUFrF24fpjtsn3qahjKuK6BfFVYYKiG6gN3GTdPL6_c/?imgmax=800&quot; width=&quot;865&quot; height=&quot;348&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Authentication Type : Text message – Two-way OTP&amp;#160; + PIN&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6m1bu_Czi4BC3o7O1SdcDeS0F4VeqGv82Vugud-spi81-DSOJRkzLX7pgil2nbEX38yehUy5wkbf3khID-S_AMc85GW2wTiw1uXbw4QHDm3Vz1C_t_T7tGBz-064SFk4lkIPeLFnTXeY/s1600-h/image%25255B56%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRbZt873vtmaJnbK84lQPtIXkFAOkiQ52TTxQ_edku_I-TR5A0CjnVBjLbrfOlMnFqx_MnWXr5xUdjNYuD5r-ulVFN2hKKgY_0kGk-epg1VF_di5yNjRLFrfOngLKHBkfi-61zJnQOuSQ/?imgmax=800&quot; width=&quot;542&quot; height=&quot;225&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;font color=&quot;#0000ff&quot;&gt;Expected Result&lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In this mode, user will be prompted for first authentication using a user name and password and then the second authentication is based on&amp;#160; a text message containing a One-Time Passcode (OTP) + PIN.&amp;#160;&amp;#160; The user must reply to the same&amp;#160; text message by entering the provided OTP + their personal PIN to complete the authentication request as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGKRzRQkSZa91KC_i_xBBd3lw9YURBhYUVMi2nVQeh7wgWCyoFYFLQkFjVJQ9cYcLgvn3ls3TiPcPJjLsdsIq18YsnajrIK058YsjPuBqMUW_61RjduoVj0FCPYSWpsts8RIlk7EEOWGg/s1600-h/image%25255B60%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgR7CXpzMBZpOGMBKh2B6SmVR8iXRqXP3Hz1fSrdmnzLQO060sQSa-yIi3b0OyTZgxkuqXRftqns4MRHbzNiImHCSsaNvXdnOvzkCGB2dUSjIt3BpjFCI7mEoQFAtQWEX4TdsFc1t9acyA/?imgmax=800&quot; width=&quot;242&quot; height=&quot;419&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;I believe we have enough information and&amp;#160; screenshots for this blog &lt;img class=&quot;wlEmoticon wlEmoticon-smile&quot; style=&quot;border-top-style: none; border-left-style: none; border-bottom-style: none; border-right-style: none&quot; alt=&quot;Smile&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHN6BqHez4_saOmttDtgABQQPcAyGDkY2xLxy75uSkyjl35jBjWIFfVGwgI7tbVLUWgeRVt0OKC6JJSxYX0cxujwtsu3vFvl-XVV56ptXr8XfVvVKESWHnkP3S71EAhqn1hsqSB6THn-0/?imgmax=800&quot; /&gt;. I will cover the following authentication types in the Part-II of this blog:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Azure Authenticator application (Standard) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (PIN) &lt;/li&gt;    &lt;li&gt;Azure Authenticator application (OATH token) &lt;/li&gt;    &lt;li&gt;Third Party OATH token &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;ol&gt;&lt;!--EndFragment--&gt;&lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Type (Part I)&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Type (Part II)&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/05/azure-mfa-serverauthentication-type.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhgxnYxlHOPiEy__QZX0at1V19OwnV_EzBPT5V_bQqqu3qOlnhLNuYqxqvOKphyphenhyphenaqqoyLPVlFDON-RIGiQ1yRKKhpfVGG8vVzjc9XhYSq4MmUUg49TYcsJEKgsrQQmjIyVdRT-UcCYHuRw/s72-c?imgmax=800" height="72" width="72"/><thr:total>14</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-3827360637966657800</guid><pubDate>Sun, 01 Jan 2017 16:04:00 +0000</pubDate><atom:updated>2017-01-01T10:04:36.055-06:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">MVP</category><title>Happy New Year – Microsoft Most Valuable Professional (MVP) Award 2017</title><description>&lt;p&gt;Happy New Year – Microsoft Most Valuable Professional (MVP) Award &lt;/p&gt;  &lt;p&gt;Received the Microsoft Most Valuable Professional (MVP) award this year also. Great start to 2017!&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWfG3_Jg7O9tyPSDP-39yah4nZnZsXWOAhdx4AJQZOl2Z8_2Pjl2JrdUCZDuiBKZHFpch4viTM9KXiCsecFprnNAanG3KR-Fcd3KaojtZKReYuId9xE6ydt0QKoAY41tuMtmSov7aR1zw/s1600-h/MVP_2017%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;MVP_2017&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;MVP_2017&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgy9aGzMzcWPJRKA1hb_YGJBifIVEaQb472AJOGWjsDG9vUvcYHYgQaYLpOAZUkNu76yZHn8Gsk_uTwp6ppJu52Z0pJO3rpEk5pHj-irY7IsX-1OwKU4LSGwqJ2NMR8HPe8g6mbZveRi6s/?imgmax=800&quot; width=&quot;1514&quot; height=&quot;1354&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2017/01/happy-new-year-microsoft-most-valuable.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgy9aGzMzcWPJRKA1hb_YGJBifIVEaQb472AJOGWjsDG9vUvcYHYgQaYLpOAZUkNu76yZHn8Gsk_uTwp6ppJu52Z0pJO3rpEk5pHj-irY7IsX-1OwKU4LSGwqJ2NMR8HPe8g6mbZveRi6s/s72-c?imgmax=800" height="72" width="72"/><thr:total>13</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-5239557005654096949</guid><pubDate>Thu, 08 Dec 2016 15:22:00 +0000</pubDate><atom:updated>2016-12-08T09:23:01.596-06:00</atom:updated><title>PowerShell - Send Test Email (Office 365) Using PowerShell</title><description>&lt;div class=&quot;WordSection1&quot;&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;background:white;text-autospace:none&quot;&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;Here is a sample PowerShell script which can be to test email communication using a SMTP server. In this script, I am using Office 365   SMTP server, &lt;span style=&quot;color:darkred&quot;&gt;smtp.office365.com.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;background:white;text-autospace:none&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;background:white;text-autospace:none&quot;&gt;&lt;a href=&quot;https://1drv.ms/t/s!AuVEEHIwTxv9h4ZXLslcu1MzA8ZSqw&quot;&gt;&lt;span style=&quot;color:windowtext;text-decoration:none&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhW9hyiK13NyRhtf4CcZJkfX1uPirrEz_G8l8qeLY86kauQRBDPWneLUZrPwvpU0XlZ1KI7_4gvw9-uM6m5IfBCLy3yRW-O3G_q9zkqLuYJ1dHOUvSjGZmx0u1TSfeqFq1v5688EeQSKL4/s1600/image001-781598.jpg&quot;&gt;&lt;img src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhW9hyiK13NyRhtf4CcZJkfX1uPirrEz_G8l8qeLY86kauQRBDPWneLUZrPwvpU0XlZ1KI7_4gvw9-uM6m5IfBCLy3yRW-O3G_q9zkqLuYJ1dHOUvSjGZmx0u1TSfeqFq1v5688EeQSKL4/s320/image001-781598.jpg&quot;  border=&quot;0&quot; alt=&quot;&quot; id=&quot;BLOGGER_PHOTO_ID_6361751006235708658&quot; /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;background:white;text-autospace:none&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;background:white;text-autospace:none&quot;&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkred&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;background:white;text-autospace:none&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;Script:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$SMTPServer&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;smtp.office365.com&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$EmailFrom&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;&lt;a href=&quot;mailto:Santhosh@virtualsecuritysolutions.com&quot;&gt;Santhosh@virtualsecuritysolutions.com&lt;/a&gt;&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$EmailTo&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;&lt;a href=&quot;mailto:santhosh@ss-ts.com&quot;&gt;santhosh@ss-ts.com&lt;/a&gt;&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#Send-MailMessage Reference -  &lt;a href=&quot;https://msdn.microsoft.com/en-us/powershell/reference/5.1/microsoft.powershell.utility/send-mailmessage&quot;&gt;  https://msdn.microsoft.com/en-us/powershell/reference/5.1/microsoft.powershell.utility/send-mailmessage&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:blue&quot;&gt;Write-Host&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;`t`tSelect 1 - SMTP Test Message with No Attachmnet&amp;quot;&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-ForegroundColor&lt;/span&gt; &lt;span style=&quot;color:blueviolet&quot;&gt;Red&lt;/span&gt;  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:blue&quot;&gt;Write-Host&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;`t`tSelect 2 - SMTP Test Message&amp;quot;&lt;/span&gt; &lt;span style=&quot;color:navy&quot;&gt;  -ForegroundColor&lt;/span&gt; &lt;span style=&quot;color:blueviolet&quot;&gt;Red&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Option&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:blue&quot;&gt;Read-Host&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkblue&quot;&gt;Function&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:blueviolet&quot;&gt;EmailTest_No_Attachment&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;{ &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#with no attachement&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Cred&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:blue&quot;&gt;Get-Credential&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Sub&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;SMTP Test Message - 1 - No Attachmnet&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Bmessage&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;SMTP Test Message - 1 with Attachment&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:blue&quot;&gt;Send-MailMessage&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:navy&quot;&gt;-From&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$EmailFrom&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-To&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$EmailTo&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Subject&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$Sub&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Body&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$Bmessage&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-SmtpServer&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$SMTPServer&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Credential&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$cred&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-UseSsl&lt;/span&gt; &lt;span style=&quot;color:navy&quot;&gt;-Port&lt;/span&gt; &lt;span style=&quot;color:purple&quot;&gt;  587&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkblue&quot;&gt;Function&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:blueviolet&quot;&gt;EmailTest_With_Attachment&lt;/span&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;{ &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#with Attachment&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Cred&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:blue&quot;&gt;Get-Credential&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Sub&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;SMTP Test Message - 1 with Attachment&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$Bmessage&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;Test email body message - With Attachment&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:orangered&quot;&gt;$MyAttachment&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:darkgray&quot;&gt;=&lt;/span&gt;&amp;nbsp; &lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;C:\temp\1.docx&amp;quot;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:blue&quot;&gt;Send-MailMessage&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;  &lt;span style=&quot;color:navy&quot;&gt;-From&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$EmailFrom&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-To&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$EmailTo&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Subject&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$Sub&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Body&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$Bmessage&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Attachments&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$MyAttachment&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-SmtpServer&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$SMTPServer&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-Credential&lt;/span&gt; &lt;span style=&quot;color:orangered&quot;&gt;$cred&lt;/span&gt;  &lt;span style=&quot;color:navy&quot;&gt;-UseSsl&lt;/span&gt; &lt;span style=&quot;color:navy&quot;&gt;-Port&lt;/span&gt; &lt;span style=&quot;color:purple&quot;&gt;  587&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkgreen&quot;&gt;#&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;;color:darkblue&quot;&gt;Switch&lt;/span&gt;&lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt; (&lt;span style=&quot;color:orangered&quot;&gt;$Option&lt;/span&gt;)  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{ &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;span style=&quot;color:purple&quot;&gt;1&lt;/span&gt; {&lt;span style=&quot;color:blue&quot;&gt;EmailTest_No_Attachment&lt;/span&gt;}  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;span style=&quot;color:purple&quot;&gt;2&lt;/span&gt; {&lt;span style=&quot;color:blue&quot;&gt;EmailTest_With_Attachment&lt;/span&gt;}  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;span style=&quot;color:blueviolet&quot;&gt;default&lt;/span&gt; {&lt;span style=&quot;color:darkred&quot;&gt;&amp;quot;Invalid Selection&amp;quot;&lt;/span&gt;}  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot; style=&quot;line-height:12.0pt;mso-line-height-rule:exactly;background:white;text-autospace:none&quot;&gt;  &lt;span style=&quot;font-size:9.0pt;font-family:&amp;quot;Lucida Console&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;} &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;Script download options:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoListParagraph&quot; style=&quot;text-indent:-.25in;mso-list:l0 level1 lfo1&quot;&gt;&lt;![if !supportLists]&gt;&lt;span style=&quot;mso-list:Ignore&quot;&gt;1.&lt;span style=&quot;font:7.0pt &amp;quot;Times New Roman&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;![endif]&gt;&amp;nbsp;OneDrive - &lt;a href=&quot;https://1drv.ms/t/s!AuVEEHIwTxv9h4ZXLslcu1MzA8ZSqw&quot;&gt;  https://1drv.ms/t/s!AuVEEHIwTxv9h4ZXLslcu1MzA8ZSqw&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoListParagraph&quot; style=&quot;text-indent:-.25in;mso-list:l0 level1 lfo1&quot;&gt;&lt;![if !supportLists]&gt;&lt;span style=&quot;mso-list:Ignore&quot;&gt;2.&lt;span style=&quot;font:7.0pt &amp;quot;Times New Roman&amp;quot;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;  &lt;/span&gt;&lt;/span&gt;&lt;![endif]&gt;TechNet Gallery - &lt;a href=&quot;https://1drv.ms/t/s!AuVEEHIwTxv9h4ZXLslcu1MzA8ZSqw&quot;&gt;  https://1drv.ms/t/s!AuVEEHIwTxv9h4ZXLslcu1MzA8ZSqw&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class=&quot;MsoNormal&quot;&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;  &lt;/div&gt;  &lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/12/powershell-send-test-email-office-365.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhW9hyiK13NyRhtf4CcZJkfX1uPirrEz_G8l8qeLY86kauQRBDPWneLUZrPwvpU0XlZ1KI7_4gvw9-uM6m5IfBCLy3yRW-O3G_q9zkqLuYJ1dHOUvSjGZmx0u1TSfeqFq1v5688EeQSKL4/s72-c/image001-781598.jpg" height="72" width="72"/><thr:total>22</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1108487097282101840</guid><pubDate>Thu, 20 Oct 2016 07:00:00 +0000</pubDate><atom:updated>2016-10-27T11:57:14.038-05:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Active Directory</category><category domain="http://www.blogger.com/atom/ns#">AD</category><category domain="http://www.blogger.com/atom/ns#">PAM</category><category domain="http://www.blogger.com/atom/ns#">Windows Server 2016</category><title>Windows Server 2016–Active Directory–Part1</title><description>&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/10/windows-server-2016active-directorypart1.html&quot; target=&quot;_blank&quot;&gt;Part1 - Windows Server 2016 – Active Directory&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Part 2 - Windows Server 2016 – Active Directory – Temporary Group Memberships &lt;/li&gt;
&lt;/ol&gt;
As you know, the latest version of Windows Server - Windows Sever 2016 - is currently available. It is available in Azure as well as I mentioned &lt;a href=&quot;https://twitter.com/Santhosh_Sivara/status/786301520580972548&quot;&gt;here&lt;/a&gt;.&amp;nbsp; You can read “what is new with Windows Server 2016” in this Microsoft article &lt;a href=&quot;https://www.microsoft.com/en-us/cloud-platform/windows-server&quot;&gt;here&lt;/a&gt;.&amp;nbsp;&amp;nbsp; In general, Windows Server 2016 provides:&lt;br /&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Added layers of security&lt;/b&gt; - Enhance security and reduce risk with multiple layers of built-in protection. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;New deployment options&lt;/b&gt; - Increase availability and reduce resource usage with the lightweight Nano Server. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Built-in containers&lt;/b&gt; - Develop and manage with agility thanks to Windows Server and Hyper-V containers. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Cost-efficient storage&lt;/b&gt; - Build highly available, scalable software-defined storage and reduce costs. &lt;/li&gt;
&lt;li&gt;&lt;b&gt;Innovative networking&lt;/b&gt; - Software-defined networking to automate with cloud-like efficiency. &lt;/li&gt;
&lt;/ul&gt;
I am not going to the details of Windows Server 2016 or it’s capabilities here. You can read all that information in the above mentioned &lt;a href=&quot;https://www.microsoft.com/en-us/cloud-platform/windows-server&quot;&gt;URL&lt;/a&gt;. My plan is to start a new blog series on Windows Server 2016 and Active Directory functionalities.&amp;nbsp; To begin this, I will add a new Widows Sever 2016 to my existing Active Directory 2012 domain and promote the Widows Sever 2016 as an additional domain controller. The Domain Promotion process is very similar to the previous versions of windows.&lt;br /&gt;
There is an upgrade to Active Directory Schema. Shema can be upgraded during the domain promotion process. The new Schema or ObjectVersionNumber is 87. Some addition information is included here in &lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/2903.active-directory-active-directory-upgrade-high-level-steps.aspx&quot;&gt;my TechNet wiki article&lt;/a&gt;. You can verify this by using ADSI Edit or &lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot;&gt;DSQuery&lt;/a&gt; or PowerShell commands.&lt;br /&gt;
Get-ADObject (Get-ADRootDSE).schemaNamingContext -Property objectVersion&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-e8aVpiEPu8PdK1tpKY_GGyFhklJq2OHKEyefD126YQVkQvoqgA9FRQlLL2WsoOurM1v9m3Y3jnu7aYfQ8VYjlTVa07LwU6Y0drtq74r_kt3nwI0vuMPkMJncGpX2KuwPEztSKLMJ7aQ/s1600-h/clip_image002%25255B1%25255D.jpg&quot;&gt;&lt;img alt=&quot;clip_image002&quot; border=&quot;0&quot; height=&quot;170&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwaz0j1Y30syF1FSxgL_GBIrhhBk60MG_FDit_TIT6vtPBXGsGqqs1Jj6JG2-ldD0X_PzShrW4nsZbdZqyXApE8rjDJte69ua9aitxy2dE58049_odWwgT_74ZoN2mZ3BHq8L-doCtdsE/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image002&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
dsquery * CN=Schema,CN=Configuration,DC=labanddemo,DC=com -scope base -attr objectVersion&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9GWORdYqmjRI8-jtFyLM-PKI-O2xz_aReoYdYnm4vCXHnQqRb6Z-9afheACIXO2_zOumIb04TkigCkec562zLj6MKri7Jc_G66Jg6uV41PMdEJ4DSlHkQStWx_lhNPHoktofpxDk50Go/s1600-h/clip_image004%25255B1%25255D.jpg&quot;&gt;&lt;img alt=&quot;clip_image004&quot; border=&quot;0&quot; height=&quot;124&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGFBC_UY-swhTIAHdn90EBTVyYecpDOVFhHsRO4g67S_vdQFS8p0jp1eGYHHhLWHw9_XsyB8dW0-jWjws27jeI4rV1fNrkOxdy85GqpeEAxAPWWIzLX-ufMxmHdE1IpB9fu1yhqkXZVcA/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image004&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
As a reference, I have provided the following table that lists the Active Directory Schema and the corresponding Object Version:    &lt;table border=&quot;1&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot;&gt;&lt;tbody&gt;
&lt;tr&gt;         &lt;td width=&quot;260&quot;&gt;&lt;b&gt;Active Directory&lt;/b&gt;&lt;/td&gt;          &lt;td width=&quot;252&quot;&gt;&lt;b&gt;Object Version&lt;/b&gt;&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2000&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;13&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2003&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;30&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2003 R2&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;31&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2008&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;44&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2008 R2&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;47&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 8 Beta&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;52&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2012&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;56&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows 2012 R2&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;69&lt;/td&gt;       &lt;/tr&gt;
&lt;tr&gt;         &lt;td valign=&quot;top&quot; width=&quot;260&quot;&gt;Windows Server 2016&lt;/td&gt;          &lt;td valign=&quot;top&quot; width=&quot;252&quot;&gt;87&lt;/td&gt;       &lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
***ObjectVersion 39 - Please refer &lt;a href=&quot;http://blogs.technet.com/b/askds/archive/2011/07/15/friday-mail-sack-peevish-nediquette-edition.aspx&quot;&gt;http://blogs.technet.com/b/askds/archive/2011/07/15/friday-mail-sack-peevish-nediquette-edition.aspx &lt;img alt=&quot;clip_image006&quot; border=&quot;0&quot; height=&quot;19&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbYYtSMPbhZRrHgAA998cM1_sv00vKStpzCcl-ZBfFK1XqzMVhMEvhYAwd04BgR_D7qrQ33zuoa7imrkiW6ZBw_AaI7Z5_MLI4i3n6TUMIiYsLcujserM9OUIzU6HzNKY81gKEaIa4zeA/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; margin: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image006&quot; width=&quot;19&quot; /&gt; &lt;/a&gt;&lt;br /&gt;
Anyway, we can start this journey with DC promotion process. The following section provides step-by-step instructions.&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Join computer to your exiting Active Directory Domain. &lt;/li&gt;
&lt;/ol&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJiLt1waLu4rmeQWjnY1fVTbA0k-CwJqZV6NMK5sBbifHNHFYPUE0SoD6TFnqVTMm_tIflasvH-vvM6CRPaBj9sSR7FWyu-B9fmbOmDVTyA6I0LzNRuXQ78KlLpBNdADoOp246l2fwxwA/s1600-h/clip_image008%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image008&quot; border=&quot;0&quot; height=&quot;484&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHLLZtj0qF9Ty34jErJNHa5HSXFjBX9XkVdWpd-AZ3r7L-sH3zhQ8qoMv7mxipYHqIlB4K7s7bPKN8UJ9jhlQfjO6R-gjLpCIl2OtKMxI_LMJEWBsro0r8wyIqQPZbJqYfkHgtOWM7G4M/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image008&quot; width=&quot;325&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
2. Click OK on the Welcome window and restart the server. After the reboot, this server will be member server in your existing Active Directory Domain. By default, this server will be in Computer Container.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhX5IbQzO57oe3_3FASfaWjHay19_wMQjhPdmYgUyXGWvDpFuU8pYcf3ycDMBvb0nMg7SKWtcxSdglSyzXZ9WUjVXBcpQ8gr1VuGXYEPVobxcH1_QAvM10LD1VVY87NL-X4ezNaduUyjsM/s1600-h/clip_image010%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image010&quot; border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEJMp-KNUZRGEbbQ5jf_6mZ4DlylRwuqFHvff9_cbZbFa2KjXBb4VXfgAcnNWWqaOXhGX8G1vaEUTBFHdHYiZuPQ_SCpqjvQwEGzx4RtPLkzBk_YV9kFGPpdmBM7vQhV3VCYYuDngX7Bc/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image010&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
3. Login to the server using a domain credentials (domain\username). You need to have proper permission to upgrade the schema and add an additional domain controller.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiW4Wg2lKRdK79sR6qsEP3-Aw6QHOBAd_btjQi_6d7RbAkSKn_dZuh_LJbDoCNR6Bfou-M_mT595jPX5nmYjAUgvs0zFAW0F2Hn2DbQPzQzYgjCun55n8h4OfZMQODD4mN7IsIbx8oO1cg/s1600-h/clip_image012%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image012&quot; border=&quot;0&quot; height=&quot;358&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYOu41iucOZ_xhm3BS-oY0luo92FonY4cTEJ1G1PnyfUf8HghVXkrJIFqRG0BNR5w9r82Z1uy3G-xTWSeK4nHSQuUbLn1cKFEj3A1_yDeRHjrci_jF8pplhkCT8F5MslL5inatOdbcfas/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image012&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
4. Next step is to add &lt;b&gt;ADDS server roles&lt;/b&gt; onto your new Windows Server 2016 server. Open &lt;b&gt;Server Manger&lt;/b&gt; and select &lt;b&gt;Add Roles and Features&lt;/b&gt; option.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAugXd6PNGVjrKhjURCJLE7QnznIspKxGipq1hQ3y-Fqw_uOzsHer0lZiJjedd5fKGzTC0qCuMnpuO3jSlujeABXHNpK9Dnll1GONVyBi0nX4q4z-6pbgg3ZNDjpAM_R-l1_B_cKZZhI8/s1600-h/clip_image013%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image013&quot; border=&quot;0&quot; height=&quot;484&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgedGXDpjDF1aGgXDm9Jqktpkqo-38uNjSbAhj0YFBUd6um84AVniEqJoCgF4Mf0DS3JUC_sIcpD-u4E9jggFdaHDVE931xFb6vHS08e_Ps8LYKNou5gOMS6jGjxVEzEQ-oJAtcWs8UUDo/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image013&quot; width=&quot;584&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
5. Click &lt;b&gt;Next&lt;/b&gt; on the &lt;b&gt;Before you begin&lt;/b&gt; window.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0uPyPdyO7cHqCy_5Z7FKHsoXHwhC7Z_iYoRPj1bx9Bn6oGCNtz9tEeBF-YDB1XgQO7u9YMhVx4gyIB2EvUymUUi0RjIdomkrBmTvY3Ymk0l4NTHyiLdXzLV_jhsMWa4RSIYHK7gHkPK8/s1600-h/clip_image015%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image015&quot; border=&quot;0&quot; height=&quot;465&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ5gKlcBgSzMZSx5Y9knqRvL6RnlTeunI0598K6d-RsxL2ZQARm86vfE_huR4nw2YWoBSppdVgldVU1rUPAhSQ_bIs5-t0DinXGzMqzDjxu-2m7Mw_vFYXmaGRRHA5fz4yXC_Z59fszsM/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image015&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
6. Select &lt;b&gt;Role-based or Feature-based installation&lt;/b&gt; option. Click &lt;b&gt;Next&lt;/b&gt;.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgN3f7HZIUwiihRZnOHuPWeopSHokcPH0rE8vPQKpWTtVuqt4JD-h7bWAkjcgP1Rk28dub59QZVg33peK18NXxn3pXOmBCBM6Ia5bGKRSvdZjFgoE_Z_RzTzU2ZiVpcwL0Tm9N0-BiP6ts/s1600-h/clip_image017%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image017&quot; border=&quot;0&quot; height=&quot;461&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhuAYpiGQb59_mWZ7MjdFyVaRo3DanNdqx-FdVC6JZHsJV19fdDOqybpXhURpG3pfbAqyQsBscl89o3cOI-UkOBpC9cK26fNALLIslxOjb_QSEA2HFECL-cs957OHLXC7czyD6V9dH3Tug/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image017&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
7. On the &lt;b&gt;Select Destination Server&lt;/b&gt; window, select your local Windows Server 2016 server. Click &lt;b&gt;Next&lt;/b&gt;. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgj25E6ktNhfa6wsjNTJICBFtQAwgkEvTYXuLEIWmxA0Sirod5xNlI_cTKi1F1GZ0vjDNGwXkAXry1KWmVkGPriEJmjiM04_fEDYd56jiJLWgzTm2PGNdSK9ytQfH7jwAmaY4qL1WzhSOE/s1600-h/clip_image018%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image018&quot; border=&quot;0&quot; height=&quot;461&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwSDlLgxBKdcPMXtnf7uc1qhRGKDiIIs6Pd1HarLrrC7zn_aZBjCxa_k0wBd5tiIB1kotqSi0H2yNiAWWSPXQ-CPaN_LyxqgzZvxfSQWzWd9KvqMDftkKxbZtrrNe9TrokEmp81T-VRcA/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image018&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
8. From &lt;b&gt;Server Roles&lt;/b&gt; option, select &lt;b&gt;Active Directory Domain Services&lt;/b&gt;. Accept the additional &lt;b&gt;Role Feature&lt;/b&gt; requirements. Click &lt;b&gt;Add Features&lt;/b&gt;. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQQhDXaUCo62VWmkzxY8ldS3kQLKSQpyWgT7PMsOjCZLpKYHMhwdmryAArsyksmjVhxGiIIgzcPUmvKfsDtWWvHYX0R9gT34XpDuApo3kp9n2yO_HkSqI0i0IDzUONFJfDoTYCDG7dQvc/s1600-h/clip_image019%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image019&quot; border=&quot;0&quot; height=&quot;469&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhucnGxSBpGsMRVEujNsm2zpmr8Hhk5GHweZ0T2jYNo1Dd4yQMY7sbaXxATvXdBU206qxPDYcCOb0IBnuUdX5vtdScIu-xk1ETqfvGX7BGhvbyGjQvlp78H0Lw76Tug_nz_Yy7QkrQ5k_A/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image019&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
9. Click Next on the &lt;b&gt;Select Features&lt;/b&gt; window.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicuf_8aObZ_kE2c5jPku4jA8u3siV12giZ_iZW-UFAEKFFbptXpB_PRwupmR6sqV2Kd10P70E0BX0WrQ5RREkhIH8d_L53YuoMk3is2mudyo7Ngd293i4AFHBMtir9iYHf7e7zaCGWQVQ/s1600-h/clip_image021%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image021&quot; border=&quot;0&quot; height=&quot;462&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhj6Nb9lp-0M7RS381DvWciame9lOpIItS3E7xdPJVehHg4rzKEBgwHBj6UgbwBTcJoDsCnsmouStwztyJXzmifUfgOuMlckwMFGXZQbT93oXfdstdnCoD5m4KItOw0PjLm0vnHnhiPOuM/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image021&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
10. Click &lt;b&gt;Next&lt;/b&gt; on &lt;b&gt;Active Directory Domain Services&lt;/b&gt; window.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgF9PaJfHLWY5htvb369upCLBfLc5wSDdeI5VMQQz6rt6vGMyUzGpjX1s_nvki2h2-FrZuXqeJWttO7MqSaFlUEZvm_TdjVEtgW4nt_VO-5km7-2-VuZgoUjMJs3ypTcydeGQKhsU1VDhA/s1600-h/clip_image022%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image022&quot; border=&quot;0&quot; height=&quot;465&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqqvR3J3vekiZMEZuRu8MRJh7VsqYzovNy02lMs4eJZGBV5Xf03G_WrHIJfU4OAgciEh_WrvSwO8-mu5A69ur5ayjipE-Ty7j7KSjs64bm3lGXkN9KZaooQri8v2cnhlD8IozeEFgsMo8/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image022&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
11. Select &lt;b&gt;Install&lt;/b&gt; option to begin AD DS role installation Process.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi23L9VqcFhjBuUARO0lePVoGQiTn7viaX3mN500qeWAbar4Yd-GT5xAAi2y92ESWuGohomQNlo02z2tCGm2RvS7crqc4XIPf26_alXNZFzZ6eoll3aSICFV-TK8r2e8g-6mlcP8lMJoTc/s1600-h/clip_image024%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image024&quot; border=&quot;0&quot; height=&quot;461&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz0fW4QYIKanfcDKTGL8OANgvSv81CuD0Zce_NekdHkXoq3E2dr7-WrfuepWizFTPQWrg0HRSejeF4t0fYbfE-kYJLxZZVrVl_gNp6jncP1TYyRJVkgczzsLo-k69OSgRyzquNqgq7dbs/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image024&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
12. Now you have installed the AD DS role onto your new Windows Server 2016. Next step is to add an additional domain controller for your existing domain. As you can see on the following screenshot, you need to perform some cognition and post-deployment option to complete this task. Click &lt;b&gt;Close&lt;/b&gt;.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg23xyOQzl3HrmKEb27nPb5ftVwejlaHhDJ71p3YRplVvsFRnOHmi2uK43v5mDlB6SkcWdwkTlOA_BUbBzHNx3Vng2x1dC-QPX1rvSx7FnTHElETBJQPLKlTRpgJQx4KpRzAvuauIPcRXM/s1600-h/clip_image025%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image025&quot; border=&quot;0&quot; height=&quot;465&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5qls8wvtMDHSqsD2de8rvKC8pWCw2MNpqXBnE6Y0_nFGabBx-0CYbbqDzNkyfA8iMM7w2BQqywleKNvtiOyrnrOzs3LhN14-UHQ0pKq16O_vEND6BerESso1iTyrG__sgdphHAGXyt78/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image025&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;From &lt;b&gt;Server Manager&lt;/b&gt;, select &lt;b&gt;Promote this server to a domain controller&lt;/b&gt; option. This will initiate the DCPROMO (Yes. I still like this word!) process. &lt;/li&gt;
&lt;/ol&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdRHuhAk6yJ0Z99CFv0kmfjmvx3UgPuTC8UFT-ekvhJ6v8bo9ZjGAlBUezqcHy-h_iiU9AFzk3ykI22v1kd79xPisGywCVdReWSmCgy49qKyssg9YG19UL1awyGnlkTaZOuhxfN4KCxSM/s1600-h/clip_image027%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image027&quot; border=&quot;0&quot; height=&quot;332&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZ1r-apKcRB4wueCjzaGgwJBin3olb_av4VCNcZEGaBhRdTQ8oKe_bkzmex3tWlLrS2Zct-G5hsr8mrsyKfKhEXkNLimxpUWBgvPvXI-V_qPYmvTdtH-77PS6LFx3ODWUuNUPubzhBEWU/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image027&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
14. As you can see on the following screenshot, you have 3 options:&lt;br /&gt;
1. Add a domain controller for an existing domain&lt;br /&gt;
2. Add a new domain to an existing forest&lt;br /&gt;
3. Add a new forest.&lt;br /&gt;
4. For this exercise, you will be selecting the first option - Add a domain controller for an existing domain&lt;br /&gt;
5. If you have only one domain and this new server is part of that domain, default domain name will be listed in the &lt;b&gt;Domain&lt;/b&gt; column.&lt;br /&gt;
6. Provide a domain credential with proper permission to perform these tasks. If the current/logged in user doesn’t have sufficient permission, you can select &lt;b&gt;Change&lt;/b&gt; option to enter a new credential.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEij1q60f-1hEh-bZSQ3VY5smgdOWe2w0TizBHXMop3YxdbfTWNUxh9R-f1VkgJ3312dSazcmQruLYjf5VEmD3Cs4RqXzzAZtmR-KVu-aPygTkspdRghmY8kdR4k2RUuD8xYAZRCMyAPVZI/s1600-h/clip_image029%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image029&quot; border=&quot;0&quot; height=&quot;476&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3pHfdPwo8vJrgA0iF1feWOXggvBe_LZFe3vsHXSffXkO9ceuxwlW1DmxS4iZMnlZVq50uJdYUljlsK-JI8EVKQsC73ggmfKAL6gYEd1p-2fCD1qw3ttyBPpkoLnC06s5NdICtZLMbIK4/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image029&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
15. From the &lt;b&gt;Domain Controller Options&lt;/b&gt; window, &lt;br /&gt;
1. select the appropriate options for your environment. In my scenario, I will be selecting:&lt;br /&gt;
1. Domain Name System (DNS) server&lt;br /&gt;
2. Global Catalog (GC)&lt;br /&gt;
2. Provide a password for Directory Service Restore Mode (DSRM)&lt;br /&gt;
3. Click &lt;b&gt;Next&lt;/b&gt;.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSEa2SnGBVUgBgfKu18KWtjurEWFOP0KHLCAb-oHrH3sdLzE0S9lWwiSfDlM35K_bgtXUOgbd7UpvKiXWOmhE627VhFZ5_k_27-vg9r1AOR7bke056IhvGMFVRVK1M6qqpyKfHyPNNfmw/s1600-h/clip_image031%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image031&quot; border=&quot;0&quot; height=&quot;475&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6hjL9BoKv2y2U0eyUeSfNiXRgTt405j9HXuuTYsInpf0kJdbhGWO8ohvLyLwsiZsrBZYv-nnTUlFtzFRRtekYwq75CwlwuUHHaVA0Ksk5S6C0S4DUIEz0BmJq-VTZygkd7iJdnSi52JQ/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image031&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
16. Click &lt;b&gt;Next&lt;/b&gt; on the &lt;b&gt;DNS Options&lt;/b&gt; window. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjU0kpXVdqFE7taCUSge0DHLYf5OsdXZNQcKSRbcv6TZqFueudV8NGiG6XhBCrf-obHHiFa4d6uwY4LjjopmIaodyWa10PBJRiUnilIYhaUwxEPgkP4s8yUsdSKelAPVsoumG7OZkgT_pU/s1600-h/clip_image033%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image033&quot; border=&quot;0&quot; height=&quot;478&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgG67iJG1YmyWYEIqXKHMHXAPMxaGdgLqHFyfaNXMOUpXwEaBX-9KMY2eW8ZEmW4VjJP85B4Ea8Ue6O2yWSFiBUT33WyYBdV1GCTE29c5LDAMGnQnyspofUbtzboX4aJn_pzeE6qR13A_U/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image033&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
17. On the &lt;b&gt;Additional Options&lt;/b&gt; window, select appropriate AD data replication option. I will be selecting &lt;b&gt;Any Domain Controller&lt;/b&gt; option for this exercise. Click &lt;b&gt;Next&lt;/b&gt;.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgav6ZupLj9lifyJ8ZbyHCK0VVUzKqrFZYlpw0RoEm8_Lvg7nnbImuZ3hrTTfXtlUzPGdOrZXg3rNgR_1jZKLeIuadUl6WOPB_zroltUFa3QJYo0PqXnTNpbgR_bTWnycuensLFAm5AtJk/s1600-h/clip_image035%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image035&quot; border=&quot;0&quot; height=&quot;479&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXiQmol8XESml48I7zCp9rdQCgFYptbKnfd_FMRcHpxpZEHbwbPJzRueNzFV5OBNXqsHJYqi_Ood67FxcLGv-OJPQhsI6jH49yOFJfbbeq-C8kYVmxl4k156yUa-IPA4EI2bAWz6nfG0I/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image035&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
18. From &lt;b&gt;Paths&lt;/b&gt; window, select appropriate path for &lt;b&gt;AD Database&lt;/b&gt; and &lt;b&gt;Log file&lt;/b&gt;. Click &lt;b&gt;Next&lt;/b&gt;.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_8ipfMqb-_Fb8XT5mCKPzQuIqrXwH_ZkKEInuoHsEiqFr-QbNJPdHOv50wRMEUBN32xtUkfI7dU4jvdczNm_gaX7ryjT1nNMNLgMSiDoiHpMomjTL8YxhFKuZp8iGSusX2EvLj-khagQ/s1600-h/clip_image037%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image037&quot; border=&quot;0&quot; height=&quot;478&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCQxnMbIFJUSP3lfHYP5Dlri9WSY3BjXF5KjK-NWZewNmmmqDboQlCNnMOprgK2URzzJQkz_Yqo6CGGWuj17thJm1Q9LPs8cGDuux1u-5BB7SM5maLAHvBFFXxASBnAhGbM0hyphenhypheniq0-wZ8/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image037&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
19. The next section will perform: &lt;br /&gt;
1. &lt;b&gt;Forest and Schema peroration&lt;/b&gt; for Windows Server 2016.&lt;br /&gt;
2. &lt;b&gt;Domain Preparation&lt;/b&gt; for Windows Server 2016.&lt;br /&gt;
3. Click &lt;b&gt;Next&lt;/b&gt; to continue.&lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvLBdAzvU-9DFIKo5GedhBIhorwtc3H86TiPF7W6RoWnDVQpxl4G2e2xzNoFCvDBBv7lt131fiTauv-PWCLNPdvTI1DjQ51E6socxKhbV8MDXo-0Saby78mNN-OZTxowtp30Fdu3BUbDM/s1600-h/clip_image038%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image038&quot; border=&quot;0&quot; height=&quot;478&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiL-sJSgq3NNf7yTRHy0wmAu6XA-s7hNwV8VpjGFhyphenhyphenvdxFHz7O_T7g5u_Dly2bhwSJQeUZpdrQtvilByqO-wnYXo5nXsqC7WyciLvabLbh_8FZ8h2CAZ5_j_NYebJMrGTNgbxIoMF90Ohc/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image038&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Click &lt;b&gt;Next&lt;/b&gt; to continue and begin the &lt;b&gt;Prerequisites Check&lt;/b&gt;. &lt;/li&gt;
&lt;li&gt;Verify the &lt;b&gt;Prerequisites Check &lt;/b&gt;result. Click &lt;b&gt;Next&lt;/b&gt; to start the Domain Controller promotion process. &lt;/li&gt;
&lt;/ol&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGmVx-AVs5K4JrmD0vyz8KOhD4gEJgiDbL1jVhTjN8mocKzBGb7QxMz_a9Wahg3nwD9A4h14IxSYm8dCeCDJE3w1HZ_EquvZTBH1vG_hq1kcwNNYJ9VaTv90HDZRGFBFnlCo2EGkbfNBo/s1600-h/clip_image040%25255B1%25255D.png&quot;&gt;&lt;img alt=&quot;clip_image040&quot; border=&quot;0&quot; height=&quot;481&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8JgJaDye6S7ICSHD2BeDNEAgMFZmOKOpbZcnMAEBaMyXIf1_GmRqVNtNU2uMTTwXRo7VIKEGSQgvJNqIoURCQoNNP1Cv1AbTJfMO0O8Kz5VKv6SlBMqVTBU4oHzWIZb1O_0hdPFVqkq4/?imgmax=800&quot; style=&quot;background-image: none; border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline; margin: 0px 4px 4px 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px;&quot; title=&quot;clip_image040&quot; width=&quot;644&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
22. I have included the common Prerequisites warning information for your reference here.&lt;br /&gt;
&lt;blockquote&gt;
Windows Server 2016 domain controllers have a default for the security setting named &quot;Allow cryptography algorithms compatible with Windows NT 4.0&quot; that prevents weaker cryptography algorithms when establishing security channel sessions.&lt;br /&gt;
For more information about this setting, see Knowledge Base article 942564 (&lt;a href=&quot;http://go.microsoft.com/fwlink/?LinkId=104751&quot;&gt;http://go.microsoft.com/fwlink/?LinkId=104751&lt;/a&gt;).&lt;br /&gt;
This computer has at least one physical network adapter that does not have static IP address(es) assigned to its IP Properties. If both IPv4 and IPv6 are enabled for a network adapter, both IPv4 and IPv6 static IP addresses should be assigned to both IPv4 and IPv6 Properties of the physical network adapter. Such static IP address(es) assignment should be done to all the physical network adapters for reliable Domain Name System (DNS) operation.&lt;br /&gt;
A delegation for this DNS server cannot be created because the authoritative parent zone cannot be found or it does not run Windows DNS server. If you are integrating with an existing DNS infrastructure, you should manually create a delegation to this DNS server in the parent zone to ensure reliable name resolution from outside the domain &quot;labanddemo.com&quot;. Otherwise, no action is required.&lt;/blockquote&gt;
23. Reboot the server after completing the DCPROMO process. After the restart, the new Windows Server 2016 will be an additional domain controller in your existing domain. The Schema will be upgraded to Windows Server 2016. &lt;br /&gt;
I believe this is good for Part-1 of this blogs series. In Part-2, my plan to focus more on Active Directory related functionalities. Please post a comment here if you like to see an particular topic in this blog series.&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/10/windows-server-2016active-directorypart1.html&quot; target=&quot;_blank&quot;&gt;Part1 - Windows Server 2016 – Active Directory&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Part 2 - Windows Server 2016 – Active Directory – Temporary Group Memberships &lt;!--EndFragment--&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/10/windows-server-2016active-directorypart1.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwaz0j1Y30syF1FSxgL_GBIrhhBk60MG_FDit_TIT6vtPBXGsGqqs1Jj6JG2-ldD0X_PzShrW4nsZbdZqyXApE8rjDJte69ua9aitxy2dE58049_odWwgT_74ZoN2mZ3BHq8L-doCtdsE/s72-c?imgmax=800" height="72" width="72"/><thr:total>44</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-8010526457896220616</guid><pubDate>Wed, 05 Oct 2016 07:00:00 +0000</pubDate><atom:updated>2016-10-27T11:57:05.066-05:00</atom:updated><title>Microsoft Advanced Threat Analytics (ATA) - Attack Simulation and Demo</title><description>Microsoft Advanced Threat Analytics (ATA) is an user and entity behavior analytics solution to identify and protect protect organizations from advanced targeted attacks (APTs).&amp;nbsp; You can read more information about Microsoft Advanced Threat Analytics (ATA) &lt;a href=&quot;https://www.microsoft.com/en-us/cloud-platform/advanced-threat-analytics&quot;&gt;here&lt;/a&gt;.&amp;nbsp; The purpose of this blog is to provide a few methods which can be used to simulate and demonstrate some of the basic attacks for demo and testing purpose.&lt;br /&gt;
&lt;strong&gt;Suspicious Activity Simulation #1&lt;/strong&gt; – &lt;strong&gt;ATA Gateway Stopped Communicating&lt;/strong&gt;&lt;br /&gt;
We will start with the most obvious one! – ATA communication issue.&amp;nbsp;&amp;nbsp; In this scenario, I am using &lt;a href=&quot;https://docs.microsoft.com/en-us/advanced-threat-analytics/plan-design/ata-architecture#ata-gateway-and-ata-lightweight-gateway&quot;&gt;ATA Light Weight Gateway&lt;/a&gt;(LWGW).&amp;nbsp; In this case Microsoft Advanced Threat Analytics Gateway (ATAGateway) service should be running on Domain Controllers. &lt;br /&gt;
To simulate this scenario,&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;     Identify all Domain Controllers from the forest/domain. You can use the following &lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot;&gt;DSQUERY&lt;/a&gt; command to get all DCs from the domain.&amp;nbsp; &lt;br /&gt;
      &lt;ul&gt;
&lt;li&gt;         DsQuery Server -Forest&lt;br /&gt;
       &lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;     Stop the &lt;strong&gt;ATAGateway &lt;/strong&gt;service remotely&lt;br /&gt;
      &lt;ul&gt;
&lt;li&gt;         Here are a few scripts -&amp;nbsp; S&lt;a href=&quot;http://portal.sivarajan.com/2010/07/stopstart-or-enabledisable-service.html&quot;&gt;cript&lt;/a&gt;1 or &lt;a href=&quot;http://portal.sivarajan.com/2011/05/stop-start-disable-service.html&quot;&gt;Script2&lt;/a&gt; or &lt;a href=&quot;http://portal.sivarajan.com/p/scripts.html&quot;&gt;Script3&lt;/a&gt; – if you want to go a script based approach&lt;br /&gt;
       &lt;/li&gt;
&lt;li&gt;         Or we can use a simple SC command – &lt;strong&gt;SC \\Lab-DC01 stop ATAGateway&lt;/strong&gt;&lt;br /&gt;
       &lt;/li&gt;
&lt;li&gt;         &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIM3cSZEKIS5-0xHbJW86Vqof6h75E6M8h8i9NRZlxbCHwytmaiHdoCidxCXngFg34I4Qg7h7hFLZ3x0LBu2mOS_VXB1rz75eWq1q5PxvPHtof-nWty-KZFxhn-AwZW6lUKpdJqLjKUlI/s1600-h/image%25255B29%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;135&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_EaRvAb5Srxhsi3GFFDf-ncaJcJ63DfKYg2narkbaXXtrUa59PpSsfJiTkskqurn_ZVIcHnybJYJvsdTlpDosAWGhdywEtbPLaqiWCmEKwlhyHcz6xG9m9LbISIxzcEH5OF0N-t5Qc2s/?imgmax=800&quot; title=&quot;image&quot; width=&quot;625&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
       &lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
You will receive the following high alert – &lt;strong&gt;ATA Gateway Stopped Communicating&lt;/strong&gt; – in Health Center. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsuEb4LNdMTqUsiyCOmoHnpvr3Ue5aaXuYUmc0cCj_-YnJA5x0P8pIP2IQFJ7Ebhr0TzMRu1w7wFXU69SMw1uGh2F-i0CM6ujHOTW_xJnctgpeYqHOwWJ6qR9RxU1riy-_QRRnBCPqZUk/s1600-h/image%25255B33%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;376&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVMDtR-V6ZmKx_AkXwwG2hwqGVfFx8IfZbpqai2mhyphenhyphengZzmqway1Iy80dG5vWPQhkupgwgndnVw2gZRFlVTDQ8roVImztX5NMN7BHyW77CCXoFcml9IwYFzKyaTI06fWIZmOzNUwpeAbYg/?imgmax=800&quot; title=&quot;image&quot; width=&quot;1064&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;strong&gt;Suspicious Activity Simulation #2&lt;/strong&gt;- &lt;strong&gt;Honey Token Account Activities&lt;/strong&gt;&lt;br /&gt;
In general, the Honey Token accounts are non-interactive accounts.&amp;nbsp; These accounts can be dummy accounts for detect malicious activities.&lt;br /&gt;
To simulate this scenario,&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Create two 2 user accounts in Active Directory (ATA-Test1 and ATA-Test2) &lt;/li&gt;
&lt;li&gt;Add ATA-Test2 to Domain Admins group &lt;/li&gt;
&lt;li&gt;Get the SID of ATA-Test1 and ATA-Test2 using PowerShell or DSQUERY command      &lt;ul&gt;
&lt;li&gt;dsquery * -filter (samaccountname=ata-test1) -attr objectsid (&lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot;&gt;Reference&lt;/a&gt;) &lt;/li&gt;
&lt;li&gt;Get-ADUser Ata-test1 -Properties objectSID (&lt;a href=&quot;http://portal.sivarajan.com/search?q=script&amp;amp;x=0&amp;amp;y=0&quot;&gt;Reference&lt;/a&gt;) &lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Add this SID as Honey token accounts (&lt;strong&gt;ATA Console –&amp;gt; Configuration –&amp;gt; Detection –&amp;gt; Honeytoken Account SIDs&lt;/strong&gt;). &lt;strong&gt;Save&lt;/strong&gt; the configuration.&amp;nbsp; &lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzRgv_vegLWLnDj5tH4XMmEShE4OjgjVks-9TNYmS94_lOT5GdXgo7_T9nsMHqFzDHrAGDer_JYR1CaO4fqKWUwAmy9H2Up4KgRBGbvWuihTvqObDAGPI4NScY_AYN8rhLt16iFhAz52E/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;528&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3nxpxIaLyKC-xtZOjir-hK6xY0his2OF-4lhwYaw88P68gnBxoObwIto7OyJ8lTkgdjepBa_CBeA0ifp4HyV0SEcrT_7kPNTyWoOR3zeUH4_2SVB-b9X8Nt3VnfQAVcHFKwNQVx45h28/?imgmax=800&quot; title=&quot;image&quot; width=&quot;893&quot; /&gt;&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Establish an integrative logon session using these accounts. You can RDP into a machine use these accounts &lt;/li&gt;
&lt;/ol&gt;
&lt;em&gt;&lt;strong&gt;Honey Token accounts (non-sensitive)&lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;
You will receive the following alert/email with recommended actions in the ATA console. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOtVFpsuJyQUs_hiYTaItiBl8poRdEV1mVy2bdckKD-MknTb3-jzrwNKnoqyqn0PAmJpWXXu0UO30-KWpB-Bil-d39TVaV9zKNdqvwYaz9CeaFYgk9Idbvj_Y6SFmHk8KeqQ-dvfG7-Jg/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;529&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_mTsi1qNe98YWt3TIeE29zZCZVPfa9XkJI72EvpYoaI0gjH-hX1wzUCBnMvc79LWWeRgu9eomLN7dwpWdm922BWueO5dIeu35GVgd4WMzRibLwZuL2oi_mTbdTVhLvmsEzPLnc9vOhm4/?imgmax=800&quot; title=&quot;image&quot; width=&quot;854&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;em&gt;&lt;strong&gt;Honey Token accounts (Sensitive)&lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;
Since ATA-Test2 account is a domain admin account, you will receive the same alert with &quot;&lt;strong&gt;Sensitive (S )&quot;&lt;/strong&gt; indicating that this account is a high privileged account in Active Directory. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn8DNyu0z_KdoPvx21MnBotBgqRIoZxY-y9nIwdF1J6El1csbn7j7AEqTVPBEeNtBRjbAfHIfudxN5WX6QHKDwzyQoI91XV9v8gZX7MYNfVFq7m5uAeCm41Z2_tDHVddihTUPTDf1TUn8/s1600-h/image%25255B7%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;570&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMxxQLSgxyjwpiYfEmwetXuFVdqt3cFQaLKBLFD3QeZtn7Iwn3SnoUjLebMg4DWlVrXD0fowoZQzhCJfuJqP23IS-I2RgM8ToCO-YYB5uAFnO-aubyGrd2KMJ9NnclYIhHMdO3NZAVC-w/?imgmax=800&quot; title=&quot;image&quot; width=&quot;902&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;strong&gt;&lt;strong&gt;Suspicious Activity Simulation &lt;/strong&gt;#3&lt;/strong&gt; &lt;strong&gt;– Massive Object Deletion&lt;/strong&gt;&lt;br /&gt;
Bulk object deletion can be a suspicious activity in an Active Directory environment.&amp;nbsp; ATA can alert alert you based on massive object deletion activities. &lt;br /&gt;
To simulate this scenario,&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;Create a few users in Active directory. Here is a sample PowerShell&amp;nbsp; script which you can use to create test accounts in Active Directory &lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote&gt;
Clear      &lt;br /&gt;Import-module activedirectory       &lt;br /&gt;$pass = ConvertTo-SecureString &quot;MyPassword0!&quot; –asplaintext –force       &lt;br /&gt;for ($i=0;$i -lt 100;$i++)       &lt;br /&gt;{       &lt;br /&gt;$accountname = &quot;Test-Account$i&quot;       &lt;br /&gt;Write-Host &quot;Creating $accountname&quot; -NoNewline       &lt;br /&gt;New-ADUser –SamAccountName $accountname –name $accountname -OtherAttributes @{&#39;description&#39;=&quot;ATA Test User Account&quot;} -Path &quot;OU=Test Accounts,OU=User Accounts,DC=labanddemo,DC=com&quot;       &lt;br /&gt;Set-ADAccountPassword –identity $accountname –NewPassword $pass       &lt;br /&gt;Write-Host &quot;...Done&quot;       &lt;br /&gt;}&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;Make sure ATA is &quot;learned&quot; about these account. &lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrUUJWYryiMO2R9AiuRtkihH4TEdYvLkog22ywQ_Sh0Dzg9_lrWLns6QgqmGFJMN_QfwtoAx8WyfeHJc8TRxsIJrQsHByCA4G-yY2znJAC54AfASAk2enF_NKux92BkoM6JB1eZu3isZY/s1600-h/image%25255B25%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;96&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMrJKxbwE9r80HZ7BDG3B3gjacl648bhNQQHATWkvhwC-uyIGrYkLDu3S7iJFnEoXB4-mxSMtb-cjgCJdTqQQsTCenhmByhkYEBTTr4c-2dCsgpba4u7ArCiJZ7266mV21vTe7gPYFhJ8/?imgmax=800&quot; title=&quot;image&quot; width=&quot;195&quot; /&gt;&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;Delete these accounts from Active Directory &lt;/li&gt;
&lt;/ol&gt;
You will receive the Massive Object Deletion alert in the ATA console right away as shown below. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj749uxMIZ_Lf7xDKPR2pOfj9Fih-el6s3Nx1G3eYGVjCMRjxRNopDvMpsou6SFd3ri6myHGQMy4DXov6rQuLkFZm_B8b2dGD0RYrSNw_VozoFtwfnGotThNCxMcccgSPoAILkvfkSo2fQ/s1600-h/image%25255B19%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;577&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCAAcDtwz5CRvySc2fVZEhpYkIeTDF9-DxZCfjzf_DDLhsL46vyqhX8QQ3vQCY6FqqamXBX7kExLeibdpMC50o2iTT3laztpvemcYY1H6vDezttLa0Za9UyrOOlwGem4mzJCBFtVANYAw/?imgmax=800&quot; title=&quot;image&quot; width=&quot;1072&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;strong&gt;&lt;strong&gt;Suspicious Activity Simulation&lt;/strong&gt; #4 - &lt;/strong&gt;&lt;strong&gt;Reconnaissance using DNS&lt;/strong&gt;&lt;br /&gt;
The DNS or name resolution information in a network would be&amp;nbsp; useful reconnaissance information. In general, DNS data contains a list of all the servers and workstations and the mapping to their IP addresses. Verifying this&amp;nbsp; information may provide attackers with a detailed view of the environment allowing attackers to focus their efforts on the relevant entities. &lt;br /&gt;
For this simulation, the plan is to perform a DNS zone lookup using NSLOOKUP LS command. &lt;br /&gt;
To simulate this scenario,&lt;br /&gt;
&lt;ol&gt;
&lt;li&gt;     Logon to a remote server. &lt;br /&gt;
   &lt;/li&gt;
&lt;li&gt;     Open Command Prompt and run &lt;a href=&quot;https://technet.microsoft.com/en-us/library/cc725991(v=ws.11).aspx&quot;&gt;NSLOOKUP&lt;/a&gt; command&lt;br /&gt;
   &lt;/li&gt;
&lt;li&gt;     From the NSLOOKUP window, run LS command to list the DNS zone&lt;br /&gt;
   &lt;/li&gt;
&lt;/ol&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunTCFmscQy-Lg07o5vUkavQYVtdrrD6IY8ZyV6NWKrzTI9uZtwYyjeO-qT4n2LRc6c7vMf1RhufQl_qzC5vNBz3RmxTG-7PkqLAZOkk0RGervqHsdcvXCSpiW74suYekqV1gAvFJmW_w/s1600-h/image%25255B41%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;113&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1270oc7TQKS9_AzsK6GTpOnlTLU6aqZ1xppRUTlU8LAtrmEnrgfS8zEUxq6yxY-L_8X7cST1YE3hIyzQlmJz88wstPl7BE1YCv9sE1rE3uOUChbEM7YehRyf3EVUhv3wVjs6MMhsPdkU/?imgmax=800&quot; title=&quot;image&quot; width=&quot;668&quot; /&gt;&lt;/a&gt;&lt;br /&gt;
You will receive the following &lt;strong&gt;Reconnaissance using DNS&lt;/strong&gt; alert the ATA console. &lt;br /&gt;
&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNwZR37ZCpUadSBiGAQIn-EWYu5bmpRzSjUeA5dxq1FTEBRVHvEtS-ZMFSmQAQI8Va1oZQ2yb3CmKdxoJt5yR8YtUoYXJu32qSm4XJ3gl8jSAgogyo9LnPRBypIkc58wZox39T9UOKR7A/s1600-h/image%25255B37%25255D.png&quot;&gt;&lt;img alt=&quot;image&quot; border=&quot;0&quot; height=&quot;557&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpdtNVJVkuSFhMwPmOR6QF3VjZPdwNA_KFSq8A-W_So-Q79Xvi0FGr4fSei2S1k1nORV4UnbpZYCfpMU-bE8kQpJAx9FdavU1J_AiMOfBi3m47N-Iucf_ogQWViymQt3iZNIOw68_mHeM/?imgmax=800&quot; title=&quot;image&quot; width=&quot;860&quot; /&gt;&lt;/a&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/10/microsoft-advanced-threat-analytics-ata.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_EaRvAb5Srxhsi3GFFDf-ncaJcJ63DfKYg2narkbaXXtrUa59PpSsfJiTkskqurn_ZVIcHnybJYJvsdTlpDosAWGhdywEtbPLaqiWCmEKwlhyHcz6xG9m9LbISIxzcEH5OF0N-t5Qc2s/s72-c?imgmax=800" height="72" width="72"/><thr:total>17</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-3835455722164537749</guid><pubDate>Tue, 05 Jul 2016 07:00:00 +0000</pubDate><atom:updated>2016-07-05T07:29:47.825-05:00</atom:updated><title>Configuring Deepnet Security SafeID OATH Token with Microsoft Azure MFA Server</title><description>&lt;p&gt;&lt;strong&gt;Related Blogs:&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Configuring YubiKey / Yubico OATH Token with Microsoft Azure MFA Server&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot;&gt;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA with pGina and Local Authentication&lt;/font&gt; - &lt;a href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align=&quot;justify&quot;&gt;Microsoft Azure MFA on-premises server supports a time based OATH (OATH – TOTP) third party tokens.&amp;#160; This is an alternative to using the &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-azure-authenticator/&quot; target=&quot;_blank&quot;&gt;Azure Authenticator Mobile App&lt;/a&gt; as an OATH token.&amp;#160; You can see other MFA authentication options in my &lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Types (Part I)&lt;/a&gt; and Azure &lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; target=&quot;_blank&quot;&gt;MFA Server–Authentication Types (Part II)&lt;/a&gt; blogs.&amp;#160; The OATH tokens can be added or imported prior to being associated with a user.&amp;#160; Administrators can associate users and tokens in the Multi-Factor Authentication Server&amp;#160; or the User Portal.&amp;#160; Users can associate themselves with an OATH token during User Portal enrollment or using the OATH Token menu option when the User Portal is configured to provide this functionality.&amp;#160;&amp;#160;&amp;#160; A bulk token import and configuration is also supported by MFA Server .&amp;#160; An administrator can import OATH Token records from an input&amp;#160; file .&amp;#160; The secret keys must be in &lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot;&gt;Base32 format&lt;/a&gt;.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;This blog provides step-by-step instructions in configuring &lt;a href=&quot;http://www.deepnetsecurity.com/authenticators/one-time-password/safeid/&quot; target=&quot;_blank&quot;&gt;Deepnet SafeID OATH token&lt;/a&gt; with &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA server&lt;/a&gt;.&amp;#160; I am using DeepNet Security&#39;s SafeID Classic model for this testing.&amp;#160; You can review different token models and details on their &lt;a href=&quot;http://www.deepnetsecurity.com/authenticators/one-time-password/safeid/&quot; target=&quot;_blank&quot;&gt;website&lt;/a&gt;.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Requirements:&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;The following are the pre-requirements to complete this configuration.&amp;#160; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA on-premises server&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;http://www.deepnetsecurity.com/authenticators/one-time-password/safeid/&quot; target=&quot;_blank&quot;&gt;Deepnet SafeID hardware&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Secret Key for your DeepNet SafeID.&amp;#160; You will receive an email with Secret Key after the purchase.&amp;#160; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Review the following &lt;strong&gt;Azure MFA Server Authentication Types&amp;#160; &lt;/strong&gt;blog if you are not familiar with authentication configuration in Azure MFA Server:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;strong&gt;Azure MFA Server – Configuration for third Party OATH&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;First step in this process is to add third party OATH Tokens in Azure MFA Server. You can either add these tokens individually or perform a bulk import using an input file.&amp;#160; &lt;/p&gt;  &lt;p&gt;To add an OATH token,&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Logon to your MFA application server.&amp;#160; Open &lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt; UI and Select &lt;strong&gt;OATH Token&lt;/strong&gt; icon. &lt;/li&gt;    &lt;li&gt;Click &lt;strong&gt;Add&lt;/strong&gt; option from &lt;strong&gt;OATH&lt;/strong&gt; &lt;strong&gt;Token&lt;/strong&gt; window. &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqaRlMhc_0vvlMbtLnjq_fdAyeVvs7qrljuJmjwuRrNCVxYIl9uBUJKkRHXpDndt0eiNBYmfFKPmiRnLAOY5-5ByE0vf64jWOLIEwZkjdLx11zgW3JyxXFKSk1-E-6vkoZomCt36Bk-bA/s1600-h/image_thumb23%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb23&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb23&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAcocUuFK1Ug-ZHnOkOkLxx0bi1c6OjoU7YyyS48TKJnhJ2Y2ujdyw6u_iLssoMAKU5UCP-g5srT1lNHpmCKWW-7A3pUSCWt-sR1jOtHcs8epCnbDkECVEoVGDeWG08GX7ekfTyjJmLPc/?imgmax=800&quot; width=&quot;899&quot; height=&quot;675&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Enter your Secret Key token Details      &lt;ol&gt;       &lt;li&gt;&lt;strong&gt;Serial Number&lt;/strong&gt; – &lt;em&gt;Required&lt;/em&gt;.&amp;#160; Enter the&amp;#160; serial number of your SafeID. This will be in the back of the Secret Keyas shown below or it will be the email you received from DeepNet.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVUSOFo7O9AiRCq14omq8xYSOEw_OTTrFU8i_lGoA6KczxdHP7Z_LXu51BRQFi-IwpM0kxNQfRfoJVC9v7Yw55DAI7SxQD2KUG03ctwa-T9St9YseFAwsLuU2IL-s6vwwV1bAKJ9NFdLY/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA4_2DQkEJeqSSweXwzlxNpRgUaU1yprrkbRywPhMMdPKTMEi2Faw9zKuAqm-X0GD5h97yRQ40q0-ZOb1__m40WcyNf171qpFAzxstS44LJixb824eJp28I7IBPMuiWVGPMXh9nZZGgEI/?imgmax=800&quot; width=&quot;500&quot; height=&quot;245&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Secret Key&lt;/strong&gt; – &lt;em&gt;Required&lt;/em&gt;. This is the Secret Key (Base32).&amp;#160; You have to receive this information from DeepNet.&amp;#160;&amp;#160;&amp;#160; You will receive an email from Deepnet with Secret Key after the purchase &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Manufacturer &lt;/strong&gt;– &lt;em&gt;Optional&lt;/em&gt;.&amp;#160; Enter &lt;strong&gt;DeepNet Security&lt;/strong&gt; as the manufacturer. &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Model&lt;/strong&gt; – &lt;em&gt;Optional&lt;/em&gt;.&amp;#160; Enter &lt;strong&gt;SafeID&lt;/strong&gt; as model type.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Start date&lt;/strong&gt; – &lt;em&gt;Optional&lt;/em&gt; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Expiration date&lt;/strong&gt; – &lt;em&gt;Optional&lt;/em&gt; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Time&lt;/strong&gt; &lt;strong&gt;interval&lt;/strong&gt; – &lt;em&gt;Required&lt;/em&gt;. Select 60 seconds.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Username&lt;/strong&gt;:&amp;#160; Associate a user with this OATH token.&amp;#160; You can manually enter the username or &lt;strong&gt;Select User&lt;/strong&gt; option to identify a user.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5s4LXkS1YpbhxlsX0U5vwo4AwRnGtXVWJyZAcN1L9RQ0S4WizSJIPkssoM7t8CQ6OYtiXUmkTTK22Vp_ZIf9dhbub7D4cOUN_xoYUq1KKgNNsAj22AdwUK4x2ETksWxR5sE0tSjNFNxk/s1600-h/image%25255B7%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTF009UJLp0_CiS8QwX8Gp2uo2ECEfggWkQJbBAdKdEC8lqGG5KQqQlTqvK6hERlQjVqjakalzx5bN5xLPbiqeyCPiFP9dIrvB6YuoVTuOyNpil9u9SiXN7n4OizDz_OfsKgoM8oRbVDw/?imgmax=800&quot; width=&quot;570&quot; height=&quot;321&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt; to complete.&amp;#160; The &lt;strong&gt;Synchronize OATH Token&lt;/strong&gt; dialog will prompt for the current OATH code to synchronize the OATH token and verify the configuration. &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBAF5RkrN20sjb-Ws87TFY5zmBtzsDps6M4S86xLxbDOgi5xzv2C2AWKU68BLNbb-Zs74cC6MN0omB20QkDsPy-MZ3GlXNvHPIBTUIxgSpJT5nlqe-omBD6hHCFYg8KG5pyH9U80TGEWE/s1600-h/image%25255B11%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEdtPDCmj5s57Ra6P2N7qbTcaWpXGkU4GY6ZW6IpLJEJcE1pG2vadcwJn-en8n9ol_r4N30OjXYTob363HkdsDUWlUeyYRuAh5Aevj5e7g6KnqlqESDjZW83dc0VZh8LLJDQ31TeRsqcc/?imgmax=800&quot; width=&quot;306&quot; height=&quot;213&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;Enter the current code from DeepNet SafeID from the &lt;strong&gt;Synchronize OATH Token&lt;/strong&gt; window to complete token configuration in MFA Server.&amp;#160; Click &lt;strong&gt;OK&lt;/strong&gt;.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5_0CPv6GbTYEy_FxNwIxFMuHmdZmFAyAKftLfZQX7feLlIpXlLQrPY8Qk5Q_J2EDPtwa42r-R6jiPQb6xQxHtgXD5b73GrA_sZFEi7efM92Ke-U2cSaq13H0LwAuN0t_abD_qg2UA3mg/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGLffRgPRAxvo-0zt_hDirILrJs63LQC_NpSsZD6PeGOfMHdGeAO0_hXe35mNicrGKCy6tV7qBjZukFSlfMz_6JY5k99nMcXgFsQr1ve_RMa6zZx2fd6HkN9woaD4T6A49Ot32ppX21dQ/?imgmax=800&quot; width=&quot;586&quot; height=&quot;312&quot; /&gt;&lt;/a&gt; &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;Note1:&lt;/em&gt;&lt;/strong&gt; MFA server validates the OATH code against the OATH token secret key and synchronizes the OATH token&#39;s time if they are valid.&amp;#160; If there are not valid, you will see the following error message:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiVar-cPK8hnri5HZqnMQJlAbDEbX248_JiD5ovu-WFyUGQ6y3_rAfMl0UWPBVZXnEMS_Vvf9nnYaA8Tmtw4Ffs7QOhYlgyWdHAy-5zYK-MPRmrPk5YOU7o3n6suRrAgbC-fwEPz9bc0YA/s1600-h/image_thumb38%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb38&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb38&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidlPPA6FMrpYlN186AApM6w5Nsl46w_n9BUhMMaQirRWkkVCjARZSOfp1a3IdbyoJ8bWgaU_rOnaVLAaLyPpFIowNkReLGCUaEPBSH1T0veeYn50GV9WEbRY5TDolMlM8BIDOwUn4DyGU/?imgmax=800&quot; width=&quot;474&quot; height=&quot;180&quot; /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;Note2:&lt;/em&gt;&lt;/strong&gt; Azure Multi-Factor Authentication Server supports bulk import of token records by using an input CSV file.&amp;#160;&amp;#160; The file must be in a supported format and may be partially or fully encrypted with a password.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://1drv.ms/u/s!AOVEEHIwTxv9hsEf&quot; target=&quot;_blank&quot;&gt;Sample Input File&lt;/a&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;To perform a bulk import,&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp6aw9X2_p8oe8zFfS4eRJIkGFiPVM5x6V9b0T_GUfPCNAO_dQ0BaLW_6jPKC0hv0uPlspD6us9wSjPIKW2ZtL2n_kCUmHwmA_VjFh35SAtC4jnk6UeP11OtMRf9FaDaaswVg7pMqi9ts/s1600-h/image%25255B43%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFr6VpKaF7SKLkrlUaLrL-xZyn-IyE5cZ6rIwrF7hNHZgUVuQwK9PsrnhBUDK39j6tfkEeAtbo2_KvOIzoti_nMhQHi-3NXsklacW14HUI0MNRWAKwWE2fhJ2XWU5Zr5tlAD4hvMjsuGY/?imgmax=800&quot; width=&quot;1027&quot; height=&quot;667&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;Note3:&lt;/em&gt;&lt;/strong&gt; you may receive the following error message when you click on Import button. There is an update/hotfix for this issue.&amp;#160; &lt;/p&gt;  &lt;p&gt;Unhandled exception has occurred in your application.&amp;#160; If you click Continue, the application will ignore this error and attempt to continue.&amp;#160; If you click Quit, the application will close immediately.&amp;#160; &lt;/p&gt;  &lt;p&gt;Could not load file or assembly ‘PfPskcClr, Version=0.0.0.0, Culture=neutral, PublicKey Token=null’ or one of its dependencies.&amp;#160; A strongly-named assembly is required.&amp;#160; (Exception from HRRESULT:0X8013100)    &lt;br /&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiWSNNmndCUnSLUK5K6_iosZ3xNecActK5x8vH6iavMudgAle2FdOiMJ5X1iV3kyQicxVuHBJzXfD_W4QF80FziwoUB1qVww2K1_HVD_cbfAXz1b8ZGOf4VQcrr25nti3X_y-Ko4YBmd84/s1600-h/image%25255B47%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEik5ZCdzrKNd6erQqOyfBmpBtesX4qWFE8zcKztgJX6nz6WoWeEsc9d_zOea_jNWFBpHdQFeviXCVv7V_kx1poMAPFk7zYj1nNFgFZzp2EYLUHzTPD5b8IltdBvNGpiHaUynJ1V6SG2FOA/?imgmax=800&quot; width=&quot;462&quot; height=&quot;371&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Azure MFA Server – End User Validation &lt;/strong&gt;&lt;strong&gt;Using DeepNet SafeID OATH Token&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The final step in this process is to validate the DeepNet SafeID configuration and authentication experience from an end user perspective.&amp;#160; &lt;/p&gt;  &lt;p&gt;To configure OATH token as the authentication type for an end user:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;From &lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt; UI, Select &lt;strong&gt;Users&lt;/strong&gt; icon &lt;/li&gt;    &lt;li&gt;From right pane, open the user properties by double clicking the user object. &lt;/li&gt;    &lt;li&gt;This will open &lt;strong&gt;User Properties / Edit User&lt;/strong&gt;&amp;#160; window as shown below.&amp;#160; Make sure that the &lt;strong&gt;OATH Token&lt;/strong&gt; is selected as the authentication type for this test user.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLtXg1s2YVQPjpu8YGNimGnrHS5qaQCTC5rq0aW7PADXtPTdYJGxh8tA-I14dz77QgT9-JvxV_wDP0logAWvU7w0mmz8aVaJFFSAonffhRtICByX4eBEhZuXaBhNnJ_IFaOd3lTutD6IA/s1600-h/image%25255B19%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6Jj1WmEOMhjcAXQbHWZMnXXZn7RG40ecoNZxl4OVJStvUO9Qs863P5v1k72cBlWowJOKknI1WRdfHu1kcnaJe6eoexlEhP92X7ijUTiebOku6G2sxxZ8-1sSUz5jO2Ypnl44GKQ21CI0/?imgmax=800&quot; width=&quot;678&quot; height=&quot;606&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;To validate this configuration, select out test user object and from the bottom of the window, select &lt;strong&gt;Test&lt;/strong&gt; option.&amp;#160;&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhSxQHMLNs0RJATOSRHmeMrcUH3zMGJ9YJca7lU7A8EVUJ_thulepMB9FUj4muC-hiYvloM9uCXYa4VjKOGBaAl-Clnhf9oOt6sXRGnbLbC_h0Wi-Xub8OzXlHXT0uwKab1SwRy_A248Mc/s1600-h/image%25255B23%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvV3FNId7spl0GmIx5gpPB5Auhs1A4TErNFs8AgopYOp2Bl-WxNwqNqvQcTL2suax7t-PmhQQ1gDFPuhuUteQFqOVPO98vsmvVwf_ShhM2ASg1c_xtLB8QATGxMUcsjBc8iNhulXBunPU/?imgmax=800&quot; width=&quot;1029&quot; height=&quot;668&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;User will be prompted for first /primary authentication using a user name and password. Enter the &lt;strong&gt;User&lt;/strong&gt; &lt;strong&gt;name &lt;/strong&gt;and &lt;strong&gt;Password&lt;/strong&gt; for the user, then click &lt;strong&gt;Test&lt;/strong&gt;.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHtgyg6ZwzGfL9MG33zWn9oF54ktjlVVajgMuJ0u-_nxQrV1312HUjhauquvrlnHyrP55lkEaCN-vqdnlxaaDAoCkngOIHL-H_5_5tCRBFIPo2k8pb4ZQspBcvGC24VYmVbDzLvJ0N4Os/s1600-h/image%25255B27%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUn7rAjyYVeO2wWvfGi1Pg9APF6Md1H1AaFTJBHR-DAnnPSzP4y0lib7Zsrf2n3a2ABT-4jhqH6TNJDpjRt_DXmll36leSfBWA4rS-4OeomVnLgzJmosn-OKQ3DQROCLa160OtvrRKiHw/?imgmax=800&quot; width=&quot;415&quot; height=&quot;192&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Then it will prompt you for the secondary authentication.&amp;#160; In this scenario, it the OATH Code.&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVdAe0OIJacfNNJH4KJqCNqMLpIUloB4BGPohWUvI13gL7Al02WhcQ2DgJUc6fys4vUKKIAFgPYBPUTCIQUqZS4feTxoweTIm5-oWBx2PkJtyiFs232XLWZqJwfkzoYSlcbr9FiEGH_TQ/s1600-h/image_thumb52%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb52&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb52&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgW6oaao-0TAaHshWKSkBTHkgxHWHHweh9qF2d83J_5BTqO37FtLKlgR2rFuEfQD5wm0uOXPBnRQjEAk_EAjaptSxwKdeaOqTgSdQo-xzHcIEasQNvC5KClztJ6bt9e-wP7YVsX6XjmIDU/?imgmax=800&quot; width=&quot;317&quot; height=&quot;139&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Get the current OATH code from your DeepNet SafeID.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHvHpbO6MDOCyIi811lAaZFuHnLzH0R8hT-L-4P6ydq1fhU-LPa8q6ZkU5RsL3qa5E60iXNGpy-o6OE7ixTs1oSlfxGPv0Tl2b9PuQNhaAefHPSKEmTFFXn8RYM7V4leavNWe0e3Ut2to/s1600-h/image%25255B35%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjv-eXUVEXhrCGBYH3P_t7wwjS1X6wgzuH4XF3ctbApICIHlQdFEBzmjNew9OxzUY5h_SRwBXczun7neRAofWSHquSqudfj6IdwUMM8UM7XWjCmXN-VnnXTqubSCcLVaHVlzlf-9dB_jLc/?imgmax=800&quot; width=&quot;586&quot; height=&quot;312&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Enter the current code in the &lt;strong&gt;OATH Code&lt;/strong&gt; window in the MFA application .&amp;#160; Click &lt;strong&gt;OK&lt;/strong&gt;.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRkEtgwxNHnE8PtXEJgSoh4wa8rxMZUJNeM6kihQvnMlSzEKQraShFoIYPceHA0A8kVF0uKKx14QsCCA5Lh1GrX2nZbHBXQYUlpcaY8lNUoLB_2Ekd-Clxz2cj3e0GJRizTUm90QxKPIU/s1600-h/image%25255B39%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh3lg7LeYupmHxTkZXAfZc65Bo52ON9mLKQosNlzucQX71WNbYWBaklBQ1ny61x9TKltJH7cKn92SAUpElGMDdMNb4MsWTHM6BFFihn16zyqenBfdLCXt9GOsJX35_1r9mTWdPo7G0YJpw/?imgmax=800&quot; width=&quot;313&quot; height=&quot;136&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;You will see the authentication status/result as shown below:&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRRhZ57zr-QYUH83lURnUe6ZWa3HjtveVW8hxv0RF8aj6KMTNMADAp8ndWW9IHyYwQ3gCC21Dr_xUSYeG4aL2Mgp2dMgkazzGbd4PEey1fqEg9fBS9xwMMAJmVmdF_54Jqalwa07eE-Tc/s1600-h/image_thumb49%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb49&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb49&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaeWuOFzLWGL7m2fHno3Y8GgnMZaq7kiQA13BAbD5KIIfkkzYPyVUmmFEgq-wj_brtdU6GzOoyabNCrtYb1an3eCTKnQrlxboumzCDB8D4RvqIxVl5ZTcCRGb_wG4MoB9ih23cUIZ9WHo/?imgmax=800&quot; width=&quot;263&quot; height=&quot;180&quot; /&gt;&lt;/a&gt; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;Related Blogs:&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Configuring YubiKey / Yubico OATH Token with Microsoft Azure MFA Server&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&quot;&gt;http://portal.sivarajan.com/2016/06/configuring-yubikey-yubico-oath-token.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA with pGina and Local Authentication&lt;/font&gt; - &lt;a href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/07/configuring-deepnet-security-safeid.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiAcocUuFK1Ug-ZHnOkOkLxx0bi1c6OjoU7YyyS48TKJnhJ2Y2ujdyw6u_iLssoMAKU5UCP-g5srT1lNHpmCKWW-7A3pUSCWt-sR1jOtHcs8epCnbDkECVEoVGDeWG08GX7ekfTyjJmLPc/s72-c?imgmax=800" height="72" width="72"/><thr:total>15</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-2270300234257526683</guid><pubDate>Mon, 27 Jun 2016 07:00:00 +0000</pubDate><atom:updated>2016-07-05T07:25:07.342-05:00</atom:updated><title>Configuring YubiKey / Yubico OATH Token with Microsoft Azure MFA Server</title><description>&lt;p&gt;&lt;strong&gt;Related blogs:&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Configuring Deepnet Security SafeID OATH Token with Microsoft Azure MFA Server&amp;#160; - &lt;a title=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot; href=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot; target=&quot;_blank&quot;&gt;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;Azure MFA with pGina and Local Authentication - &lt;a title=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot; href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Azure MFA Server –Authentication Types (Part I) - &lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;Azure MFA Server –Authentication Types (Part II) - &lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p align=&quot;justify&quot;&gt;Microsoft Azure MFA on-premises server supports a time based OATH (OATH – TOTP) third party tokens.&amp;#160; This is an alternative to using the &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-azure-authenticator/&quot; target=&quot;_blank&quot;&gt;Azure Authenticator Mobile App&lt;/a&gt; as an OATH token.&amp;#160; You can see other MFA authentication options in my &lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; target=&quot;_blank&quot;&gt;Azure MFA Server–Authentication Types (Part I)&lt;/a&gt; and Azure &lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; target=&quot;_blank&quot;&gt;MFA Server–Authentication Types (Part II)&lt;/a&gt; blogs.&amp;#160; The OATH tokens can be added or imported prior to being associated with a user.&amp;#160; Administrators can associate users and tokens in the Multi-Factor Authentication Server&amp;#160; or the User Portal.&amp;#160; Users can associate themselves with an OATH token during User Portal enrollment or using the OATH Token menu option when the User Portal is configured to provide this functionality.&amp;#160;&amp;#160;&amp;#160; A bulk token import and configuration is also supported by MFA Server .&amp;#160; An administrator can import OATH Token records from an input&amp;#160; file .&amp;#160; The secret keys must be in &lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot;&gt;Base32 format&lt;/a&gt;.&amp;#160; This blog provides step-by-step instructions in configuring &lt;a href=&quot;https://www.yubico.com/products/yubikey-hardware/&quot; target=&quot;_blank&quot;&gt;YubiKey OATH token&lt;/a&gt; with &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA server&lt;/a&gt;.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Requirements:&lt;/strong&gt; &lt;/p&gt;  &lt;p&gt;The following are the pre-requirements to complete this configuration.&amp;#160; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-get-started-server/&quot; target=&quot;_blank&quot;&gt;Microsoft Azure MFA on-premises server&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://www.yubico.com/products/yubikey-hardware/&quot; target=&quot;_blank&quot;&gt;YubiKey hardware&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://www.yubico.com/products/services-software/personalization-tools/&quot; target=&quot;_blank&quot;&gt;YubiKey Personalization Tool&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://www.yubico.com/support/downloads/&quot; target=&quot;_blank&quot;&gt;YubiCo Authenticator Application&lt;/a&gt; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;YubiKey Personalization Tool – Installation and Configuration &lt;/strong&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;Microsoft Azure MFA server supports only the &lt;a href=&quot;https://tools.ietf.org/html/rfc6238&quot; target=&quot;_blank&quot;&gt;OATH TOTP (time-based)&lt;/a&gt; tokens.&amp;#160; So you need to make sure that your YubiKey is in &lt;strong&gt;Yubico OTP Mode&lt;/strong&gt; using the YubiKey Personalization Tool. Other configurations are optional for Microsoft Azure MFA server configuration and testing.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;The &lt;strong&gt;YubiKey Personalization Tool &lt;/strong&gt;can be used to program the two configuration slots. Also, it can be used to personalize the YubiKey in the following modes:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Yubico OTP &lt;/li&gt;    &lt;li&gt;OATH-HOTP &lt;/li&gt;    &lt;li&gt;Static Password &lt;/li&gt;    &lt;li&gt;Challenge-Response &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Download &lt;a href=&quot;https://www.yubico.com/products/services-software/personalization-tools/&quot; target=&quot;_blank&quot;&gt;YubiKey Personalization Tool&lt;/a&gt; and run &lt;em&gt;&lt;strong&gt;yubikey-personalization-gui-3.1.24.exe&amp;#160; &lt;/strong&gt;&lt;/em&gt;file to compete the tool installation.&amp;#160; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Insert YubiKey into the USB port.&amp;#160; You may see the &lt;strong&gt;Device Setup&lt;/strong&gt; windows as shown below.&amp;#160; Complete the drive installation process.&amp;#160; &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgsijlDY12UgDj4KmDajzJDYl60qqoT3tEOS256NT2BMvtNt5b_3wF4QrKO-eszmjERx4GDHzAcKZV1bF94EiN2XJPXRZ5iZA8TpWE8t-6Vxr3xWtY7nh1aZ8B3ojBAD26aWxQ1qji9Qb0/s1600-h/image%25255B6%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDg9aRfj3Tm7gYmkSivDkfb8ZIxBgg4ex66ZORmhGtZ87FxhdwiX6eyLsb26sdHHXFHqshm1AO4nb4BeEEXHrBlGEO7AHvq4q3r3tbuxEeo6Y4ys5gckloz0LKBSlCvJL9DRVBxYRIMAE/?imgmax=800&quot; width=&quot;618&quot; height=&quot;312&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Open &lt;strong&gt;YubiKey Personalization&lt;/strong&gt; &lt;strong&gt;Tool&lt;/strong&gt;. Make sure:       &lt;ol&gt;       &lt;li&gt;&lt;strong&gt;YubiKey Personalization&lt;/strong&gt; &lt;strong&gt;Tool &lt;/strong&gt;has successfully identified your YubiKey.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgglq8r-6wyepPEefwu0QPI9-No_F31aNRkHvsjcV35r7uuR2vBb3FuSxMvBdb3TdmztKrcNYJN3G97tCc4cVQKe1a4CIJTAyHuuOl-hqBxAN_4Jerj3-Nqz_1v4hHEDHORSYsyLDVL5ck/s1600-h/image%25255B14%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3OCvpgUZ_GvdoPI0ySGFUWPhOfbKvvHzQPa-CSsMaBEtcQqdJ7KzSDX4fiDaGhuZ5ArtOlhycaCKCybztoFs5ip0NdV73pXNKqPkrhxftkbaw4TDVpUndGZcesy5solDHE2Elj-Uf9VU/?imgmax=800&quot; width=&quot;903&quot; height=&quot;237&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Yubico OTP&lt;/strong&gt; displayed as supported method in &lt;strong&gt;Features Supported&lt;/strong&gt; section.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-5gAsaXBcI9QcSHw1TW1d3yZT_bXdEzmlcNOhcz2V7CSsSSGJFsfdtMTS_Tt_fObG6xLNig9G5QSPYDkq_6yrTpQe78hsqetPLFOeTNOy7zU8VbnUC5szIn4ywWUnz1e8n5eBKme5iEQ/s1600-h/image%25255B20%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE9M2nuYXviqKoq7V-B-Rpd8YgQSJOW5qACDx_KDmzK6gFzCrWP1IpV60Rxh4oP0XdT9PiD9RA3rfUFUb9HglqGelZ0oesy4QJG28jSzoL5QHMnUsxHFYEtlTWLpSdhR4vlz01srQ-vCg/?imgmax=800&quot; width=&quot;174&quot; height=&quot;231&quot; /&gt;&lt;/a&gt; &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt;    &lt;li&gt;You will see all the current OTP configuration in Yubico OTP tab shown below. I am going to a use the default configuration for this testing.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTkAHVJp1sPjKzdBcvGUxTyAvMkxOmmPAG4LwraP5w-rZmxUDNv_wmQAmCxTve8iyQXkCylkf582VPr8Af1uHoFZQ6Oonvy3vbae5kk1Z2tn3U8Et3NLP4qtd0cjiS8H3rZa_8zq10_ug/s1600-h/image%25255B24%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrtKnC-wtHswrUDNW7_B33fi4afHq3amXwyDFSInU1irFaoVV25jok_jIX8TxOJUy6mDQ7oooIlbhf9WsSLNHxVyZxtlMuZo6DswItbt0ckd2z4EjeLOHrTCumStnHJli75c8M-9aJOWM/?imgmax=800&quot; width=&quot;720&quot; height=&quot;438&quot; /&gt;&lt;/a&gt; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;YubiCo Authenticator Application – Installation and Configuration&lt;/strong&gt; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;Download &lt;a href=&quot;https://www.yubico.com/support/downloads/&quot; target=&quot;_blank&quot;&gt;YubiCo Authenticator Application&lt;/a&gt; and run &lt;em&gt;&lt;strong&gt;yubioath-desktop-3.0.1-win.exe&lt;/strong&gt;&lt;/em&gt; file to complete the application installation.&amp;#160; &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Open &lt;strong&gt;YubiCo Authenticator Application&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;From &lt;strong&gt;File&lt;/strong&gt; menu, select &lt;strong&gt;Add&lt;/strong&gt; option (&lt;strong&gt;File –&amp;gt; Add&lt;/strong&gt;) &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgO4kMxAUqRKA1ppDwsIC62LIOZPn_XWRoCuln_cQCbiu_P8xx4CVBPlxN2ObbeR1o9HJif3OIsomZX8eA7hPXNgciiiEPScONw99VhlJ0N5jAvV4E1b_rLNosUvVSHkXccVJLcfFiSg4k/s1600-h/image%25255B28%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi90TMBqmoKLWIiuPgd-MTmQrApPH7rnWf4EvCcltDjd8Trvj_6yN64HBT-Xnyi9ZXoCkXwXqGJlYdUp64aJoUDjhyphenhyphenfBJN8kap0FzK4RQqd6NrBjYumkivTKlxga1x-p1FwNs2ae1bqRec/?imgmax=800&quot; width=&quot;329&quot; height=&quot;174&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;From the &lt;strong&gt;New Credential&lt;/strong&gt; window:       &lt;ol&gt;       &lt;li&gt;Enter &lt;strong&gt;Credential Name&lt;/strong&gt; – An identifier or a display name for the credential. &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Secret Key&lt;/strong&gt; – It is a Base32 key. &lt;a href=&quot;https://tools.ietf.org/html/rfc4648&quot; target=&quot;_blank&quot;&gt;Review this&lt;/a&gt; If you are not familiar with supported numbers or characters in Base32 encoding.&amp;#160; &lt;/li&gt;        &lt;li&gt;Select &lt;strong&gt;Time based (TOTP)&lt;/strong&gt; option.&amp;#160; Microsoft Azure MFA server supports only the &lt;a href=&quot;https://tools.ietf.org/html/rfc6238&quot; target=&quot;_blank&quot;&gt;OATH TOTP (time-based)&lt;/a&gt; tokens.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Number of digits&lt;/strong&gt; – You can select 6 or 8 digits as OATH token length. &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpTmWD-lvVaZ6_KLN_bZC2cDoko2zx-DAYclBWA2ijvFmUXvW6i3DeqAnY1kyY7uPVIc4ookHIxHsDtmqV0MtsikzN3wtUAWFEcKJ5yrZtQlYarpxu6az3rMNe_sfyMgAjiNHQ3nHj4Bo/s1600-h/image%25255B39%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrfUUPwBOLl2CawtgOD2jiEYapeDhbtA8C27EIyNRJUQT2ZDtl0KZEj3rgPH2kO2XRJkyR9pKcqPiefr1GcPa2NDKtGy3YbDF3AzIsNGad0Ncq_Qc-MN6Zrvka7c8aQGdXVDwDWReoQZc/?imgmax=800&quot; width=&quot;329&quot; height=&quot;208&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Require touch&lt;/strong&gt; -&amp;#160; If you select this option, end user has to touch the YubiKey to generate an OATH token.&amp;#160; User will prompted with the following message: &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimu6PgCghWnlqwzlseqnMgmWnSrX_tK3sADrNw7Ed01st66qHWnBnJnJ5hPighnFKDCUwVWHblGlWldEwDNquQdZ3xzoN1emoF6VX9SQU9Rp9sU5JOdOAhsgnR-pD8z5LPQzEZMvZ4W_o/s1600-h/image%25255B31%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfeYy3HXcD1p8CzajZBlhqXwVbs_LkiNw01Bw7SXeNUebM8fc9UBpWrwoO3nGPwbZyNcJ-58VSgEhL8FggBiepBFedi8VTKul7fA9psTJS9uHfHgP__MdVCDGiT8reml1IjwoiCuokErU/?imgmax=800&quot; width=&quot;210&quot; height=&quot;101&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt; to save the configuration &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjHzAGwMGGMeRp1uPzfAxrMyRHq2GPy7ZkeFsgqoYN1uoVxWsGAmuDxPhyLLrwzEtFaodTpMiWdPJgxCsne9ZZSz1ZOZqs9NExLcyvAKDgSJshFJvFwFVaBtvNegWrx8IG4ejrQBLd1Ck/s1600-h/image%25255B43%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQtT7JZGo6mHLxdFnVQeQqknwHVeg7s5zyx9hwgUusTma6wXz3KCID-rE_9n6hfPKz986dNiONpFC-esKTs2BSudVUu5PAPdfoPdzXKTR048Nvp3zu32HiLq06jGl2qmQzkhoebaGzb4o/?imgmax=800&quot; width=&quot;269&quot; height=&quot;282&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;You will see the newly add account in the Yubico Authenticator window.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEip6JCyDzRZIk35AhQRKZU0QoI_BxgSHXrs1hkkY0AfFHo94SVeG1iF09Y5SIbMcAa9kbjgZN21WjtHtKfmIK_-txT0To4rviT8q7m1PQApjGJDlypHIXsCLWFkS_XWzNvJr1q42khH6yM/s1600-h/image%25255B47%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhkONPCn31P7bTHSoa-KyiycRsgyo8desblo7Nn85khxH9QVAAQjFm_BQOZa2Yu9q9N3WyYc-LCbLgprzY5E9WNdBaI55DimvqDBjhadayxdvRSYMyd0TllIHLbrlEStMhHO-Ksk9auLUE/?imgmax=800&quot; width=&quot;328&quot; height=&quot;150&quot; /&gt;&lt;/a&gt; &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;Now we have completed the YubiKey account configuration. We can move on to Azure MFA server to configure the OATH token. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Azure MFA Server - Configuration for third Party OATH&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Review the following &lt;strong&gt;Azure MFA Server Authentication Types&amp;#160; &lt;/strong&gt;blog if you are not familiar with authentication configuration in Azure MFA Server:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part I)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;font color=&quot;#0000ff&quot;&gt;Azure MFA Server –Authentication Types (Part II)&lt;/font&gt; - &lt;a title=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot; href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;To add OATH Token in Azure MFA Server, &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Open &lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt; UI and Select &lt;strong&gt;OATH Token&lt;/strong&gt; icon. &lt;/li&gt;    &lt;li&gt;Click &lt;strong&gt;Add&lt;/strong&gt; option from &lt;strong&gt;OATH&lt;/strong&gt; &lt;strong&gt;Token&lt;/strong&gt; window. &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMa0kFX0LV-nEHGmJNArs3gI0pgTk9UbWh7uLaZ0SxuE3AbDjN_mLLj9uE9qsOvvMpwH49odAZEK2027w4fFaMIroj44ePhVRSZ_InFNfyyddfnsyITEvZeGG00xkTBqifcv6M1zFwIjg/s1600-h/image%25255B51%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjF4q67QDagL8jjwHczuLipXWG3_4fvEcS1ESDhRt2-kPbNAPAmHVv_jJ2sLG56H-7vAnmgFBkcFZFX2ULynKgIlqsOdZhNA-OjwRXiSm0E3YQre7FIz3W-wkUekmoc_CdblytFVvpBq4g/?imgmax=800&quot; width=&quot;899&quot; height=&quot;675&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Enter your YubiKey token Details      &lt;ol&gt;       &lt;li&gt;&lt;strong&gt;Serial Number&lt;/strong&gt; – Required.&amp;#160; Enter the YubiKey serial number. This will be in the back of the Yubikey as shown below: &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgckrjKB1l_4HmaTy5bkVIH8eUmlm1RCp33yDZpxwLGwAgQpyhFAyD3jv8p1tNXHmY-r3Dvi8qhwTcpZ111iwkf5gEHbYHH7jhmbnTDkzUqO8JWxaywNoAYlBHA0wz16rzQERDnZWNRCrE/s1600-h/image%25255B54%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtUx4sY2mdn9ukE4ZXiPWnbay2iqfKXxfbzbHaoN1slUJlyby01k1d-3qByJn2Ix_YpFNcUqk6uOJyurdXJUeKpxrGd1gex4pRNQTi2iNBNdfES20IvSHRS66MCTRlhT7O3V1l0NGXUTM/?imgmax=800&quot; width=&quot;126&quot; height=&quot;244&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Secret Key&lt;/strong&gt; – Required. This is the Secret Key (Base32) you have configured using the Authentication Application.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Manufacturer &lt;/strong&gt;– Optional.&amp;#160; Enter &lt;strong&gt;Youbico&lt;/strong&gt; as the manufacturer. &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Model&lt;/strong&gt; – Optional.&amp;#160; Enter your YubiKey model type.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Start date&lt;/strong&gt; – Optional &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Expiration date&lt;/strong&gt; – Optional &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Time&lt;/strong&gt; &lt;strong&gt;interval&lt;/strong&gt; – Required. You can select the default 30 seconds value.&amp;#160; By default, YubiKey changes the 6-8 digit code&amp;#160; every 30 seconds.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;strong&gt;Username&lt;/strong&gt;:&amp;#160; Select the user for this OATH token.&amp;#160; You manually enter the username or &lt;strong&gt;Select User&lt;/strong&gt; option to identify a user.&amp;#160; &lt;/li&gt;        &lt;li&gt;Click &lt;strong&gt;OK&lt;/strong&gt; to complete.&amp;#160; The &lt;strong&gt;Synchronize OATH Token&lt;/strong&gt; dialog will prompt for the current OATH code to synchronize the OATH token and verify the configuration. &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDUSzo7qKW-rxD0k9Lq7ulyJIrE1SEmQ8dooo7WDT6MRKO7rHHJZSNanPz3Vf7rxQ8zuaVmGdmx_7noOgvBpMbfrAyxFbEKdIGEWe0CcTBvPTv8XXu59XmMNTmeWOGENOtBlgC6PdOgFE/s1600-h/image%25255B65%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiX6UHJAf_Eg9t7OXF-4I9BhhcSgUsqjxhc-9Z2wBHFSCzxdOTQdGApUfKcb30aSP6w6IAVBl-6NUBNwAasddhS8EP_GCflTzQtWkfVloSqxnXcoi1DzPjnBLy_cQgjTSA0Ovj_jzIlEYA/?imgmax=800&quot; width=&quot;308&quot; height=&quot;216&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;Generate a new OATH from Yubico Authentication app using the &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYQiYX46A60qTWOfQrib5ycoM6qohrz5QdgaSWo86wU49aLVFJ5-S5ZFBFOo-3tGOa0i5MxZPXgZHTCv1v_Nii9p2NFK-h02bULFBYSefsd3VXtzezKMUUXbKYzdLyQA1rwr5JcZjvcTQ/s1600-h/image%25255B74%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhWaIDK6F2O9jPKWGsdq-Mkvfk-yS-9MD_ExfAU0roiCU0Oo_Y7p0D2xx40-2V0c-937KqQHR__6godLOZS5a8VO7KRXs6MrlXAD4aIXJDWEEplKRAQWUe_DpExNgaxj48d1JSH77zmil4/?imgmax=800&quot; width=&quot;35&quot; height=&quot;32&quot; /&gt;&lt;/a&gt;button.&amp;#160; &lt;/li&gt;        &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWegOfvFuSzEPMzszZjVyOGYB8AuBwt6fEM2BbYJgJSIJo2kNBVfXDL4DHZ_nFyWWAglemIqEd812NBK1-dE0F0d8rLJa5ajlE1ui7XLwP9SZ7oFgS11k1c4ry76vGztSlGe406cRL1Lw/s1600-h/image%25255B66%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEing_BZ8aab7vBDvebpL5qJhQ86uc-jYrBYrAi7EP3brmCdLnEPkUad9R70_-xNQOCKv7g2ytyC315wKu6QtOBtHMJOBudn7FoLwH-ySDHBj7nFOf6IAkVGcGkqAjPE-GDra6sSbDAajkY/?imgmax=800&quot; width=&quot;325&quot; height=&quot;246&quot; /&gt;&lt;/a&gt; &lt;/li&gt;        &lt;li&gt;Enter this code in the &lt;strong&gt;Synchronize OATH Token&lt;/strong&gt; window to complete token configuration in MFA Server.&amp;#160; &lt;/li&gt;     &lt;/ol&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;Note1:&lt;/em&gt;&lt;/strong&gt; MFA server validates the OATH code against the OATH token secret key and synchronizes the OATH token&#39;s time if they are valid.&amp;#160; If there are not valid, you will see the following error message:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjm1by2zJJXlxX5hld0KHdP11ItO2NWLBYHfUnR8uJaqH1DeiNukaXNWxHWZM2U2RuNsIxUU3APw4HAIh_J0zvQ7wZqR4dj6KygykFmsZTHS_gZgLMXT2NA3MC3nvWzmPJdgV7jebtLrik/s1600-h/image%25255B78%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQvaOc2QJ4764Afu3FMX8TUklVGPVYvFbZ1Z2BLmVJaxPcxUU2ltlSTSYr0Z5MISr0FRK7yJB3EII0BqDoTsJakHpBq6vBFxNkWoii3ihYX_nm_8AqVkKbIIrNYZuFnR8EbRyrQREmGW4/?imgmax=800&quot; width=&quot;474&quot; height=&quot;180&quot; /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;Note2:&lt;/em&gt;&lt;/strong&gt; Azure Multi-Factor Authentication Server supports bulk import of token records by using an input CSV file.&amp;#160;&amp;#160; The file must be in a supported format and may be partially or fully encrypted with a password.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://1drv.ms/u/s!AOVEEHIwTxv9hsEg&quot; target=&quot;_blank&quot;&gt;Sample Input File&lt;/a&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;To perform a bulk import,&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;Select OATH Token icon and select &lt;strong&gt;Import&lt;/strong&gt;.&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;Select the input file and click &lt;strong&gt;Import&lt;/strong&gt;. &lt;/div&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaenOyT-r8JGaQ5qya2Q_vO2sLtuLLhYHB2LE1xsewlNQFMB-FW5WSxZikFiGekdDbFGwySoyJ1pIpaitjLpiEwIu_BdbT4M_d_F2P4GLRNEFUJNb577fBOU0USXiF4lUgwhg3hWK8Jdc/s1600-h/image_thumb%25255B19%25255D%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb[19]&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb[19]&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglCpp8Hu2n7WQ52r-4X1L3J_ul-Pqi8X0XYbzUbProRCgUMawAYczh4goqqLzPtAtvKwUjjRUd5J4L5FAIbfmNI7k1QDhezC-lBF4jgKLtccUtM0NlSiaom5vTnChO5lwfw-QJIAWtjRI/?imgmax=800&quot; width=&quot;1027&quot; height=&quot;667&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;&lt;em&gt;Note3:&lt;/em&gt;&lt;/strong&gt; you may receive the following error message when you click on Import button. There is an update/hotfix for this issue.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;em&gt;Unhandled exception has occurred in your application.&amp;#160; If you click Continue, the application will ignore this error and attempt to continue.&amp;#160; If you click Quit, the application will close immediately.&amp;#160; &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;Could not load file or assembly ‘PfPskcClr, Version=0.0.0.0, Culture=neutral, PublicKey Token=null’ or one of its dependencies.&amp;#160; A strongly-named assembly is required.&amp;#160; (Exception from HRRESULT:0X8013100)&lt;/em&gt;     &lt;br /&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhI1lpdSfWrK3kPXSakF-XdllhCceEGch5EUekRpYG3pzMzKQ-JcRMKwQajoT_x6T0lz4zWSojl-MSFELVg0QbHwiePoeb8LO4o5Fe5VoMpleyorkouXCCp4beNBqpsQgAw1JicOeP5HwM/s1600-h/image_thumb%25255B21%25255D%25255B2%25255D.png&quot;&gt;&lt;img title=&quot;image_thumb[21]&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image_thumb[21]&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0cv6FLw2WsUNjLusJySN0sWNdNKuhPJ-DQzo0nRUZRicFYwj2W51aD9-XzY9Qt67xCPJfA9_SO-MJBc_H_ex9I9I1j_nTPX3Tm4hpFu1vKbKhNHieJTnOhmIphUSrkX4halSeITjMLUE/?imgmax=800&quot; width=&quot;462&quot; height=&quot;371&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Azure MFA Server – End User Validation &lt;/strong&gt;&lt;strong&gt;Using YubiKey OATH Token&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The final step in this process is to validate the YubiKey configuration and authentication experience from an end user perspective.&amp;#160; &lt;/p&gt;  &lt;p&gt;To configure OATH token as the authentication type for an end user:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;From &lt;strong&gt;Multi-Factor Authentication Server&lt;/strong&gt; UI, Select &lt;strong&gt;Users&lt;/strong&gt; icon &lt;/li&gt;    &lt;li&gt;From right pane, open the user properties by double clicking the user object. &lt;/li&gt;    &lt;li&gt;This will open &lt;strong&gt;User Properties / Edit User&lt;/strong&gt;&amp;#160; window as shown below.&amp;#160; Make sure that the &lt;strong&gt;OATH Token&lt;/strong&gt; is selected as the authentication type for this test user.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6ax6nNbm_7wtINhmwHnNRE2LShJ0Xd05CIigEiZcXXKggKCQ5LOsQN4L3ghglJSsKu64hCG90V4RmE-h6zv5-lN6zGpoiTqgQoKbNfsHog8hz7_-mjvt0EIZX-vEPmQvVtXRF8gaYqrk/s1600-h/image%25255B90%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjo1axRp5AhxMDvmXb7nvpstVkUVl3qWuks24f3C2Q9bnqRh3OibBidGy8mMsFExfRS7lfNR48RCCUFncmFLsqbwYSguP-SU4shGdIggdfSBHUSWRRFolSxNcxrwQXGWp91VOh67ITGaAs/?imgmax=800&quot; width=&quot;678&quot; height=&quot;607&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;To validate this configuration, select out test user object and from the bottom of the window, select &lt;strong&gt;Test&lt;/strong&gt; option.&amp;#160;&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLZYkj2G6_io_XSyD770NAxoKABvnfcmKBObMIQSlfti4KYfuhkVeRK9ihdEHoFF8Vy6KHG2Z5o1cShflLp_Adf_YIeeQp6R4NX8MFIc97yfbBa1CC7NQRSoNlCsyxffYt_VeuWtM9b7E/s1600-h/image%25255B4%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlTIiPL6x0XS8miMfLmQ4NddBrpCkAnXlqMgNI0lVQabYmXzIAXm_WgognmTmdKyY6mfM9IYjzKC_EqjMKdq7bE1E8sfTQgtwsV5gjmlzpkGtNu5fCXSLs9WgWkeQFEyLSouNRpPH3Lhc/?imgmax=800&quot; width=&quot;1029&quot; height=&quot;674&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;User will be prompted for first /primary authentication using a user name and password. Enter the &lt;strong&gt;User&lt;/strong&gt; &lt;strong&gt;name &lt;/strong&gt;and &lt;strong&gt;Password&lt;/strong&gt; for the user, then click &lt;strong&gt;Test&lt;/strong&gt;.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVBvC2BV6esgq4Ll8hrMFGUll-5wEkV-Fx5ZlETnD5mnZLAn58MZbJ52BS5f_Q3qqS7jzxA5D0pOqZrFJkvcYHPMYxj3OAC9ZVSvBogqZ-VBOStrySjIxL5KF65uoEalPC1MJ-FYo-R3k/s1600-h/image%25255B94%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZRwAA1jDHpjuDigXa6Rll8gzl-btXYrBSBarGZ-nv0sclKpkR3KFJIlRuNGaohRyErwI1wpoqLNUxeY__IV3iivQsxVKDi3nsf7kYccAovJfG7NAFLuPlWuyPa9me_InV7kyAU53IjPs/?imgmax=800&quot; width=&quot;417&quot; height=&quot;195&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Then it will prompt you for the secondary authentication.&amp;#160; In this scenario, it the OATH Code.&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgThvUzKuIehr7TLCJNknJ4TiT5B-6JlUqjHw5iog7rnoMWCtop4R_mPv_d_F5S9t7bXLqzu_KqepiXRiMhBl00eKPqydeKdqxHEnnq96BCRIlNoin_hw3bfJHdiwXExo9RJPQniG41zbE/s1600-h/image%25255B110%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinBbM0Bx7uKkRU2HWL5wd_matwf9BSqmGkbVSHICutTJzDz6k0rUbX26zjahAXz53r06oSt3EQMEtaDqfEPgmQW1TYLay201k0y7pB6isdMrORaMLO8JGLgCMiNXh5T3TZmPf2kbENmPE/?imgmax=800&quot; width=&quot;317&quot; height=&quot;139&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;To generate a new OATH code, open &lt;strong&gt;Yubico Authenticator App&lt;/strong&gt; and&amp;#160; pressing the &lt;a&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;file:///C:/Users/SanthoshSivarajan/AppData/Local/Temp/OpenLiveWriter1425683934/C9F885A12646/image.png&quot; width=&quot;35&quot; height=&quot;32&quot; /&gt;&lt;/a&gt;button .&amp;#160; The OATH code will be displayed as shown below: &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiz1X58WfXF94-3gRUsIu0LiBtWWC32hAf5uGJmoghAHDfi6ptZK76cIuTeOvjFbhCnqQJFEDcrsow0s3705pvLwwAu3-25VxQO8IF7125UVLBxIk_v1x9CIaCCcVlkjS4L_VU16HBMkO0/s1600-h/image%25255B109%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbGMicA3SPj2klUGQjT7tKSh8WziDj61WRjqVMXaK3Dkai2M-rt8Q13FZzzLxJhoE1XLK1CAveJL_o9xViX_zCK0_CQngNg0ITUhhLaeR4cRXPfi20c_fYL_V1CXnRA1uhx6IaNu-ZWiw/?imgmax=800&quot; width=&quot;335&quot; height=&quot;168&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Enter the current OATH code in the &lt;strong&gt;OATH Code&lt;/strong&gt; in the MFA application window.&amp;#160; Click &lt;strong&gt;OK&lt;/strong&gt;.&amp;#160; &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4deyImwMykoAikbWkE1-TmSQQvOuldIq9QgGzbpBRxrhzSN7XzMwHA7uphUtsdMlMMjlPWaboNZuqV6tWU3Ux8U_bN3gWsDPBjlOaYu_8IpT41L765dJ8jf7vGRJKlH8Ds5lYel0jMlw/s1600-h/image%25255B108%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdo-CTJlviQbK5srodXCsis1z7UYoR-HX4jge5kFBlrbxIAU-czdRF0QmlTqSN2YWzNPt5DTP5s-wYIgsleC18OliS3GVpdp7BDWouWI7CUaBuEMz8a9S_g60qOlo0gxA_XkwEcOJriVU/?imgmax=800&quot; width=&quot;324&quot; height=&quot;142&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;You will see the authentication status/result as shown below:&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyhT6rTSpfkqqBfvOXBO0ILARH96K1Ju_Jze8miiNyCuzvT8XnrSh4wOvI_P-7RfHqK6s1hIpQuHyPaasO2l8k0-sJMlxtSAhOUhZVXLUs9lBz54V-pJrp_B7nAJ5NP-Fb8uatibYVVAg/s1600-h/image%25255B107%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdX2bQOXN5P3r512A9wCUmMbIHHdYoxnjCleSggBxDl_9fnT3p-G3kP3ztIG6j5_NXbWiaVIvuHKGWs9iXxqUDBUtfzhMFJQtlldFsBPJv-5cK4MdkWTpCAQsBRkuCSEbaiEz-s4cKXss/?imgmax=800&quot; width=&quot;263&quot; height=&quot;180&quot; /&gt;&lt;/a&gt; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;Related blogs:&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Configuring Deepnet Security SafeID OATH Token with Microsoft Azure MFA Server&amp;#160; - &lt;a title=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot; href=&quot;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&quot; target=&quot;_blank&quot;&gt;http://portal.sivarajan.com/2016/07/configuring-deepnet-security-safeid.html&lt;/a&gt; &lt;/p&gt;    &lt;p&gt;Azure MFA with pGina and Local Authentication - &lt;a title=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot; href=&quot;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&quot;&gt;http://portal.sivarajan.com/2015/09/azure-mfa-with-pgina.html&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Azure MFA Server –Authentication Types (Part I) - &lt;a href=&quot;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/05/azure-mfa-serverauthentication-type.html&lt;/a&gt; &lt;/p&gt;    &lt;p&gt;Azure MFA Server –Authentication Types (Part II) - &lt;a href=&quot;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&quot;&gt;http://portal.sivarajan.com/2016/06/azure-mfa-server-authentication-type.html&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/06/configuring-yubikey-yubico-oath-token.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhDg9aRfj3Tm7gYmkSivDkfb8ZIxBgg4ex66ZORmhGtZ87FxhdwiX6eyLsb26sdHHXFHqshm1AO4nb4BeEEXHrBlGEO7AHvq4q3r3tbuxEeo6Y4ys5gckloz0LKBSlCvJL9DRVBxYRIMAE/s72-c?imgmax=800" height="72" width="72"/><thr:total>14</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-5057016778413246275</guid><pubDate>Thu, 23 Jun 2016 07:00:00 +0000</pubDate><atom:updated>2016-06-27T07:36:03.839-05:00</atom:updated><title>Advanced Threat Analytics–Attack Simulation and Demo–Part1</title><description>&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/advanced-threat-analyticsattack.html&quot; target=&quot;_blank&quot;&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part1&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part2&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part3&lt;/strong&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;Microsoft Advanced Threat Analytics (ATA) is an user and entity behavior analytics solution to identify and protect protect organizations from advanced targeted attacks (APTs).&amp;#160; You can read more information about Microsoft Advanced Threat Analytics (ATA) &lt;a href=&quot;https://www.microsoft.com/en-us/cloud-platform/advanced-threat-analytics&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;.&amp;#160; The purpose of this blog is to provide a few methods which can be used to simulate and demonstrate some of the basic attacks for demo and testing purpose.&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;strong&gt;Suspicious Activity Simulation #1&lt;/strong&gt; – &lt;strong&gt;ATA Gateway Stopped Communicating&lt;/strong&gt;&amp;#160;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;We will start with the most obvious one! – ATA communication issue.&amp;#160;&amp;#160; In this scenario, I am using &lt;a href=&quot;https://docs.microsoft.com/en-us/advanced-threat-analytics/plan-design/ata-architecture#ata-gateway-and-ata-lightweight-gateway&quot; target=&quot;_blank&quot;&gt;ATA Light Weight Gateway&lt;/a&gt; (LWGW).&amp;#160; In this case Microsoft Advanced Threat Analytics Gateway (ATAGateway) service should be running on Domain Controllers.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;To simulate this scenario, &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;Identify all Domain Controllers from the forest/domain. You can use the following &lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot; target=&quot;_blank&quot;&gt;DSQUERY&lt;/a&gt; command to get all DCs from the domain.&amp;#160;&amp;#160; &lt;/div&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div align=&quot;justify&quot;&gt;DsQuery Server -Forest&lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;Stop the &lt;strong&gt;ATAGateway &lt;/strong&gt;service remotely &lt;/div&gt;      &lt;ul&gt;       &lt;li&gt;         &lt;div align=&quot;justify&quot;&gt;Here are a few scripts -&amp;#160; S&lt;a href=&quot;http://portal.sivarajan.com/2010/07/stopstart-or-enabledisable-service.html&quot; target=&quot;_blank&quot;&gt;cript&lt;/a&gt;1 or &lt;a href=&quot;http://portal.sivarajan.com/2011/05/stop-start-disable-service.html&quot; target=&quot;_blank&quot;&gt;Script2&lt;/a&gt; or &lt;a href=&quot;http://portal.sivarajan.com/p/scripts.html&quot; target=&quot;_blank&quot;&gt;Script3&lt;/a&gt; – if you want to go a script based approach &lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div align=&quot;justify&quot;&gt;Or we can use a simple SC command – &lt;strong&gt;SC \\Lab-DC01 stop ATAGateway&lt;/strong&gt;&lt;/div&gt;       &lt;/li&gt;        &lt;li&gt;         &lt;div align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIM3cSZEKIS5-0xHbJW86Vqof6h75E6M8h8i9NRZlxbCHwytmaiHdoCidxCXngFg34I4Qg7h7hFLZ3x0LBu2mOS_VXB1rz75eWq1q5PxvPHtof-nWty-KZFxhn-AwZW6lUKpdJqLjKUlI/s1600-h/image%25255B29%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_EaRvAb5Srxhsi3GFFDf-ncaJcJ63DfKYg2narkbaXXtrUa59PpSsfJiTkskqurn_ZVIcHnybJYJvsdTlpDosAWGhdywEtbPLaqiWCmEKwlhyHcz6xG9m9LbISIxzcEH5OF0N-t5Qc2s/?imgmax=800&quot; width=&quot;625&quot; height=&quot;135&quot; /&gt;&lt;/a&gt;&lt;/div&gt;       &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p align=&quot;justify&quot;&gt;You will receive the following high alert – &lt;strong&gt;ATA Gateway Stopped Communicating&lt;/strong&gt; – in Health Center.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsuEb4LNdMTqUsiyCOmoHnpvr3Ue5aaXuYUmc0cCj_-YnJA5x0P8pIP2IQFJ7Ebhr0TzMRu1w7wFXU69SMw1uGh2F-i0CM6ujHOTW_xJnctgpeYqHOwWJ6qR9RxU1riy-_QRRnBCPqZUk/s1600-h/image%25255B33%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjVMDtR-V6ZmKx_AkXwwG2hwqGVfFx8IfZbpqai2mhyphenhyphengZzmqway1Iy80dG5vWPQhkupgwgndnVw2gZRFlVTDQ8roVImztX5NMN7BHyW77CCXoFcml9IwYFzKyaTI06fWIZmOzNUwpeAbYg/?imgmax=800&quot; width=&quot;1064&quot; height=&quot;376&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Suspicious Activity Simulation #2&lt;/strong&gt;- &lt;strong&gt;Honey Token Account Activities&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;In general, the Honey Token accounts are non-interactive accounts.&amp;#160; These accounts can be dummy accounts for detect malicious activities. &lt;/p&gt;  &lt;p&gt;To simulate this scenario, &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Create two 2 user accounts in Active Directory (ATA-Test1 and ATA-Test2) &lt;/li&gt;    &lt;li&gt;Add ATA-Test2 to Domain Admins group &lt;/li&gt;    &lt;li&gt;Get the SID of ATA-Test1 and ATA-Test2 using PowerShell or DSQUERY command      &lt;ul&gt;       &lt;li&gt;dsquery * -filter (samaccountname=ata-test1) -attr objectsid (&lt;a href=&quot;http://social.technet.microsoft.com/wiki/contents/articles/3537.active-directory-domain-services-ad-ds-commands-and-scripts.aspx&quot; target=&quot;_blank&quot;&gt;Reference&lt;/a&gt;) &lt;/li&gt;        &lt;li&gt;Get-ADUser Ata-test1 -Properties objectSID (&lt;a href=&quot;http://portal.sivarajan.com/search?q=script&amp;amp;x=0&amp;amp;y=0&quot; target=&quot;_blank&quot;&gt;Reference&lt;/a&gt;) &lt;/li&gt;     &lt;/ul&gt;   &lt;/li&gt;    &lt;li&gt;Add this SID as Honey token accounts (&lt;strong&gt;ATA Console –&amp;gt; Configuration –&amp;gt; Detection –&amp;gt; Honeytoken Account SIDs&lt;/strong&gt;). &lt;strong&gt;Save&lt;/strong&gt; the configuration.&amp;#160; &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzRgv_vegLWLnDj5tH4XMmEShE4OjgjVks-9TNYmS94_lOT5GdXgo7_T9nsMHqFzDHrAGDer_JYR1CaO4fqKWUwAmy9H2Up4KgRBGbvWuihTvqObDAGPI4NScY_AYN8rhLt16iFhAz52E/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi3nxpxIaLyKC-xtZOjir-hK6xY0his2OF-4lhwYaw88P68gnBxoObwIto7OyJ8lTkgdjepBa_CBeA0ifp4HyV0SEcrT_7kPNTyWoOR3zeUH4_2SVB-b9X8Nt3VnfQAVcHFKwNQVx45h28/?imgmax=800&quot; width=&quot;893&quot; height=&quot;528&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Establish an integrative logon session using these accounts. You can RDP into a machine use these accounts &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;em&gt;&lt;strong&gt;Honey Token accounts (non-sensitive)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;You will receive the following alert/email with recommended actions in the ATA console.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgOtVFpsuJyQUs_hiYTaItiBl8poRdEV1mVy2bdckKD-MknTb3-jzrwNKnoqyqn0PAmJpWXXu0UO30-KWpB-Bil-d39TVaV9zKNdqvwYaz9CeaFYgk9Idbvj_Y6SFmHk8KeqQ-dvfG7-Jg/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_mTsi1qNe98YWt3TIeE29zZCZVPfa9XkJI72EvpYoaI0gjH-hX1wzUCBnMvc79LWWeRgu9eomLN7dwpWdm922BWueO5dIeu35GVgd4WMzRibLwZuL2oi_mTbdTVhLvmsEzPLnc9vOhm4/?imgmax=800&quot; width=&quot;854&quot; height=&quot;529&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;strong&gt;Honey Token accounts (Sensitive)&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Since ATA-Test2 account is a domain admin account, you will receive the same alert with &amp;quot;&lt;strong&gt;Sensitive (S )&amp;quot;&lt;/strong&gt; indicating that this account is a high privileged account in Active Directory.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhn8DNyu0z_KdoPvx21MnBotBgqRIoZxY-y9nIwdF1J6El1csbn7j7AEqTVPBEeNtBRjbAfHIfudxN5WX6QHKDwzyQoI91XV9v8gZX7MYNfVFq7m5uAeCm41Z2_tDHVddihTUPTDf1TUn8/s1600-h/image%25255B7%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMxxQLSgxyjwpiYfEmwetXuFVdqt3cFQaLKBLFD3QeZtn7Iwn3SnoUjLebMg4DWlVrXD0fowoZQzhCJfuJqP23IS-I2RgM8ToCO-YYB5uAFnO-aubyGrd2KMJ9NnclYIhHMdO3NZAVC-w/?imgmax=800&quot; width=&quot;902&quot; height=&quot;570&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;strong&gt;Suspicious Activity Simulation &lt;/strong&gt;#3&lt;/strong&gt;&amp;#160;&lt;strong&gt;– Massive Object Deletion&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Bulk object deletion can be a suspicious activity in an Active Directory environment.&amp;#160; ATA can alert alert you based on massive object deletion activities.&amp;#160; &lt;/p&gt;  &lt;p&gt;To simulate this scenario, &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Create a few users in Active directory. Here is a sample PowerShell&amp;#160; script which you can use to create test accounts in Active Directory &lt;/li&gt; &lt;/ol&gt;  &lt;blockquote&gt;   &lt;p&gt;Clear      &lt;br /&gt;Import-module activedirectory       &lt;br /&gt;$pass = ConvertTo-SecureString &amp;quot;MyPassword0!&amp;quot; –asplaintext –force       &lt;br /&gt;for ($i=0;$i -lt 100;$i++)       &lt;br /&gt;{       &lt;br /&gt;$accountname = &amp;quot;Test-Account$i&amp;quot;       &lt;br /&gt;Write-Host &amp;quot;Creating $accountname&amp;quot; -NoNewline       &lt;br /&gt;New-ADUser –SamAccountName $accountname –name $accountname -OtherAttributes @{&#39;description&#39;=&amp;quot;ATA Test User Account&amp;quot;} -Path &amp;quot;OU=Test Accounts,OU=User Accounts,DC=labanddemo,DC=com&amp;quot;       &lt;br /&gt;Set-ADAccountPassword –identity $accountname –NewPassword $pass       &lt;br /&gt;Write-Host &amp;quot;...Done&amp;quot;       &lt;br /&gt;}&lt;/p&gt; &lt;/blockquote&gt;  &lt;ol&gt;   &lt;li&gt;Make sure ATA is &amp;quot;learned&amp;quot; about these account. &lt;/li&gt;    &lt;li&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrUUJWYryiMO2R9AiuRtkihH4TEdYvLkog22ywQ_Sh0Dzg9_lrWLns6QgqmGFJMN_QfwtoAx8WyfeHJc8TRxsIJrQsHByCA4G-yY2znJAC54AfASAk2enF_NKux92BkoM6JB1eZu3isZY/s1600-h/image%25255B25%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMrJKxbwE9r80HZ7BDG3B3gjacl648bhNQQHATWkvhwC-uyIGrYkLDu3S7iJFnEoXB4-mxSMtb-cjgCJdTqQQsTCenhmByhkYEBTTr4c-2dCsgpba4u7ArCiJZ7266mV21vTe7gPYFhJ8/?imgmax=800&quot; width=&quot;195&quot; height=&quot;96&quot; /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Delete these accounts from Active Directory&amp;#160; &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;You will receive the Massive Object Deletion alert in the ATA console right away as shown below.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj749uxMIZ_Lf7xDKPR2pOfj9Fih-el6s3Nx1G3eYGVjCMRjxRNopDvMpsou6SFd3ri6myHGQMy4DXov6rQuLkFZm_B8b2dGD0RYrSNw_VozoFtwfnGotThNCxMcccgSPoAILkvfkSo2fQ/s1600-h/image%25255B19%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCAAcDtwz5CRvySc2fVZEhpYkIeTDF9-DxZCfjzf_DDLhsL46vyqhX8QQ3vQCY6FqqamXBX7kExLeibdpMC50o2iTT3laztpvemcYY1H6vDezttLa0Za9UyrOOlwGem4mzJCBFtVANYAw/?imgmax=800&quot; width=&quot;1072&quot; height=&quot;577&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;strong&gt;Suspicious Activity Simulation&lt;/strong&gt; #4 - &lt;/strong&gt;&lt;strong&gt;Reconnaissance using DNS&lt;/strong&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;The DNS or name resolution information in a network would be&amp;#160; useful reconnaissance information. In general, DNS data contains a list of all the servers and workstations and the mapping to their IP addresses. Verifying this&amp;#160; information may provide attackers with a detailed view of the environment allowing attackers to focus their efforts on the relevant entities.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;For this simulation, the plan is to perform a DNS zone lookup using NSLOOKUP LS command.&amp;#160; &lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;To simulate this scenario, &lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;Logon to a remote server.&amp;#160; &lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;Open Command Prompt and run &lt;a href=&quot;https://technet.microsoft.com/en-us/library/cc725991(v=ws.11).aspx&quot; target=&quot;_blank&quot;&gt;NSLOOKUP&lt;/a&gt; command&lt;/div&gt;   &lt;/li&gt;    &lt;li&gt;     &lt;div align=&quot;justify&quot;&gt;From the NSLOOKUP window, run LS command to list the DNS zone&lt;/div&gt;   &lt;/li&gt; &lt;/ol&gt;  &lt;p align=&quot;justify&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjunTCFmscQy-Lg07o5vUkavQYVtdrrD6IY8ZyV6NWKrzTI9uZtwYyjeO-qT4n2LRc6c7vMf1RhufQl_qzC5vNBz3RmxTG-7PkqLAZOkk0RGervqHsdcvXCSpiW74suYekqV1gAvFJmW_w/s1600-h/image%25255B41%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1270oc7TQKS9_AzsK6GTpOnlTLU6aqZ1xppRUTlU8LAtrmEnrgfS8zEUxq6yxY-L_8X7cST1YE3hIyzQlmJz88wstPl7BE1YCv9sE1rE3uOUChbEM7YehRyf3EVUhv3wVjs6MMhsPdkU/?imgmax=800&quot; width=&quot;668&quot; height=&quot;113&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p align=&quot;justify&quot;&gt;You will receive the following &lt;strong&gt;Reconnaissance using DNS&lt;/strong&gt; alert the ATA console.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNwZR37ZCpUadSBiGAQIn-EWYu5bmpRzSjUeA5dxq1FTEBRVHvEtS-ZMFSmQAQI8Va1oZQ2yb3CmKdxoJt5yR8YtUoYXJu32qSm4XJ3gl8jSAgogyo9LnPRBypIkc58wZox39T9UOKR7A/s1600-h/image%25255B37%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpdtNVJVkuSFhMwPmOR6QF3VjZPdwNA_KFSq8A-W_So-Q79Xvi0FGr4fSei2S1k1nORV4UnbpZYCfpMU-bE8kQpJAx9FdavU1J_AiMOfBi3m47N-Iucf_ogQWViymQt3iZNIOw68_mHeM/?imgmax=800&quot; width=&quot;860&quot; height=&quot;557&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://portal.sivarajan.com/2016/06/advanced-threat-analyticsattack.html&quot; target=&quot;_blank&quot;&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part1&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part2&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Advanced Threat Analytics–Attack Simulation and Demo–Part3&lt;/strong&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/06/advanced-threat-analyticsattack.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_EaRvAb5Srxhsi3GFFDf-ncaJcJ63DfKYg2narkbaXXtrUa59PpSsfJiTkskqurn_ZVIcHnybJYJvsdTlpDosAWGhdywEtbPLaqiWCmEKwlhyHcz6xG9m9LbISIxzcEH5OF0N-t5Qc2s/s72-c?imgmax=800" height="72" width="72"/><thr:total>10</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1810509716671585335</guid><pubDate>Tue, 17 May 2016 07:00:00 +0000</pubDate><atom:updated>2016-05-18T07:08:03.149-05:00</atom:updated><title>Azure – Custom NameId Support in SAML Attribute</title><description>&lt;p&gt;Now Azure supports extension attributes (1-15) as Name Identifier (nameid) in SAML token.&amp;#160; This option is available for both Gallery and Custom applications.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtJc-PRF-7X95VGpNhHpAojrHdFKlgw1W-kv5p6R1wuHR3TDtvnyffg3DKX9mk9_uQOq2eBI-Ku3KT1gXJ_FT-dJonNr9mqTGt5m_A-D7oqXrvooqSWN2q5BM3jUhA2W2KNI5NYTIKdS8/s1600-h/image%25255B7%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1fauYMR2kLshsxWVYHLIUV98RxdrNpQyZ5-i0V6dfmIzxPfSQEdoi-c3dARj_KniQ09omM_eIMigg7O0YixNpghCT0Z990HcIswgmmvLps__laxJYPiJwcSiiecwe5kYRVq8t0VzRrHQ/?imgmax=800&quot; width=&quot;1048&quot; height=&quot;391&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Using the Claims Editor, now you can select, Extension Attributes 1 –10 as the unique identifier.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJWZRHi8vM6QHsBRVcNyuBKb-WFqP1_XnoCZwVv-5za_HuLyHUglvzwyZZZgUfbzpJT87gu789cfEJ9wl_xXwgMRHet2j6zY-dXHP-tF_PxbGRGeWG_dSi1S0pxsKZFlrp-wHhMOD9xiw/s1600-h/image%25255B11%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUgtqvqbP0P7In7RiXpVnmKeE9eoXqZfnt892hyphenhyphen4kPTdmPUqxwID3SR6Fx0D4aJSM0lQAFgzpwtFasdwKo7lJ3eOaSVM68Sb8Ic7UzEMSLGn_2aPHpX35DYugQMaSqfeASfTq4bmU1w44/?imgmax=800&quot; width=&quot;517&quot; height=&quot;526&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Previously, we had only a few attribute options (user.mail , user.onpremisessamaccountname , user.userprinciplenae and ExtractMailPrefix() fuciton) as name identifier.&amp;#160; We couldn’t use any custom values using extension attribute.&amp;#160; &lt;/p&gt;      &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh90wD4cmTW5fgSdwS3ZTJ8JJOGs2IwUSEgnQI9YNb7Fg2b1SjEAWsP2wsljEuBh29QHAyLOs7GRjjxLVWQnrNC8srge5sZp2K5a50jt6-3GjKx17Eb30GQz-vQWJjmLc7-Xer2ZIdmNew/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhg5oyXE_sjLWFxyXQzN4cT0Rx1neaHIPzzgSKblUFVgOaVUXFd6dRbWkKwyvHoh-JlF5IgI6vbbLJsW16xcGJk2G_NCrxljQhpvWQESLOKy4S_QD6t707q-9kHYkYlRMi-7R4eN8wv6Jc/?imgmax=800&quot; width=&quot;332&quot; height=&quot;122&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/05/azure-custom-nameid-support-in-saml.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1fauYMR2kLshsxWVYHLIUV98RxdrNpQyZ5-i0V6dfmIzxPfSQEdoi-c3dARj_KniQ09omM_eIMigg7O0YixNpghCT0Z990HcIswgmmvLps__laxJYPiJwcSiiecwe5kYRVq8t0VzRrHQ/s72-c?imgmax=800" height="72" width="72"/><thr:total>5</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-26854050281889111</guid><pubDate>Tue, 03 May 2016 07:00:00 +0000</pubDate><atom:updated>2016-05-03T02:00:14.382-05:00</atom:updated><title>Azure MFA–Directory Integration Filter</title><description>&lt;p&gt;Here are a few options which you can use to filter objects from Active Directory when using&amp;#160; Directory Integration with Azure MFA.&amp;#160; The Azure on-premises MFA&amp;#160; server supports standard &lt;a href=&quot;https://msdn.microsoft.com/en-us/library/aa746475(v=vs.85).aspx&quot; target=&quot;_blank&quot;&gt;LDAP filter&lt;/a&gt;.&amp;#160; You can this filter in Directory &lt;strong&gt;Integration –&amp;gt; Synchronization –&amp;gt; User Filter: &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbOtzV7ESnfRPKOLnDJVwgOs5Tuhmc3r0b6IpW7D8U35vjD6ZUf-I_8jTYNssUtOYWXhhU5esODAxEkKFT3gqbaI1rAQeS_l96WTPx3akV86jh73WqkoVDYS63ms6VqsvDtf55_BLmW4k/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioCjvVWrnI4svtrcWRraBIBxVd5O1zMxDgD0KPY5INTLhphtcwadTuapJASfpLTZl43-QtbwiFaLpun-PwaPNoT47k-hOyynrzrbMLxzoIqlszafEym-yEQ2ik_z-HDJvQGlAQUlW-cuQ/?imgmax=800&quot; width=&quot;622&quot; height=&quot;472&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;For example,&lt;/p&gt;  &lt;p&gt;if you want to filter or include users based on a group membership, you can use the &lt;a href=&quot;https://msdn.microsoft.com/en-us/library/ms677099(v=vs.85).aspx&quot; target=&quot;_blank&quot;&gt;memberOf&lt;/a&gt; attribute with &lt;a href=&quot;https://msdn.microsoft.com/en-us/library/windows/desktop/aa366101(v=vs.85).aspx&quot; target=&quot;_blank&quot;&gt;distributedName&lt;/a&gt; of the security group as shown below: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;(memberof=CN=MFASync,OU=Groups,DC=labanddemo,DC=com)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEir1l6ENiDs9rwTIKEayvR02qnM3RidNMO-RPtcaNxaT_-eZ-g_Hiz6aY2x7WUPws6ETu9VKLHgltRDaR2TUhF5g_4M-HDKddcLzJEo4ZQyh-6pfv6dOOLKd_weFm6ZiLxmpzFYzz8kXJw/s1600-h/image%25255B17%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgBnH78rqFAY3Y4LfJkZ-iUe2w6d9Ss8jr6sfQzXR5ZKrx6YB2a0PL4A1T4ESqYEXxW5VRe62clNPJ8dHioK7ib6xm94V_po6XUxDTF4wevp7TAu73PQdCzWGUPaNcX0_XpkDNaCMF0F2o/?imgmax=800&quot; width=&quot;520&quot; height=&quot;289&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;If you want filter or include users based on an attribute value, you can use &lt;strong&gt;(attributename=value)&lt;/strong&gt; format as shown below:&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;(department=IT)&lt;/strong&gt;&lt;/p&gt; &lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9af5f_c9YWXplvtIDnHxWY943Ga49EVP1ZUsznxFNTTTJB1-nsLHidkns_zMbna7gezMvu40gm86DTH6fCWtzLLwsR3PFPSz5djXQLXfCI3-ES7vkeeCdCD3YBw9qhlUvjORhYATHY3A/s1600-h/image%25255B18%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh26Nb3AsCA3Gr1uJs5Q374XnobI5WvOlvuzSxwlH_KpwYwDSRfutZTAuReM2mlUvKoJsQbvJi6XVj9ogjTmYf6GKHhV8CHKO1vsLFnLtmoxjFarGaU8lK10AmSu3mfxH9pKSC01vvh9Fo/?imgmax=800&quot; width=&quot;542&quot; height=&quot;322&quot; /&gt;&lt;/a&gt;  &lt;p&gt;You can also use standard logical operator to combine your filter statement: &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;(|(memberof=CN=MFASync,OU=Groups,DC=labanddemo,DC=com)(department=IT))&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxDfLhw2ubncamXXPad10Be0fEoCJsjfhcnQNyCTWJgzysd0sA4db00z4E3bCaoqDlHKZ2Fizv47v0pLygxUyqNic-ZjHNyijcq1tVo-xXNC-Ry1kRW6RFlAjtOYYlHL6f8EPpmN8aGb4/s1600-h/image%25255B22%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGPtQFtKmKsJg7F3j-pVSvIIGjE9ykxGv_62MayvAJzfLu4unthQbiChoxbwR6jfNUBDmvbxnQxIFlPbewnjDUhVuV5UsAVvGgyoZPhjbFeB-kNgC_yXNoPZfQ5Il7WVjbVJXYuuixh2k/?imgmax=800&quot; width=&quot;567&quot; height=&quot;289&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/05/azure-mfadirectory-integration-filter.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioCjvVWrnI4svtrcWRraBIBxVd5O1zMxDgD0KPY5INTLhphtcwadTuapJASfpLTZl43-QtbwiFaLpun-PwaPNoT47k-hOyynrzrbMLxzoIqlszafEym-yEQ2ik_z-HDJvQGlAQUlW-cuQ/s72-c?imgmax=800" height="72" width="72"/><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-594828112088315244</guid><pubDate>Thu, 28 Apr 2016 07:00:00 +0000</pubDate><atom:updated>2016-05-02T15:49:55.376-05:00</atom:updated><title>Azure MFA -  ADFS Adaptor and pfsvcclientclr.dll Error</title><description>&lt;p&gt;&lt;strong&gt;Problem Statement:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;When using 7.0 version of Azure on-premises MFA server, you may receive an event ID 364 with “&lt;strong&gt;Could not load file or assembly &#39;pfsvcclientclr.dll&#39; or one of its dependencies. The specified module could not be found&lt;/strong&gt;” error message.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Complete Error Message &lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;System.IO.FileNotFoundException: Could not load file or assembly &#39;pfsvcclientclr.dll&#39; or one of its dependencies. The specified module could not be found.&lt;/p&gt;  &lt;p&gt;File name: &#39;pfsvcclientclr.dll&#39;&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160; at pfadfs.AuthenticationAdapter.IsAvailableForUser(Claim identityClaim, IAuthenticationContext context)&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160; at Microsoft.IdentityServer.Web.Authentication.External.ExternalAuthenticationHandler.IsAvailableForUser(Claim identityClaim, IAuthenticationContext authContext)&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160; at Microsoft.IdentityServer.Web.Authentication.External.ExternalAuthenticationHandler.ProcessContext(ProtocolContext context, IAuthenticationContext authContext, IAccountStoreUserData userData)&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160; at Microsoft.IdentityServer.Web.Authentication.External.ExternalAuthenticationHandler.Process(ProtocolContext context)&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160; at Microsoft.IdentityServer.Web.Authentication.AuthenticationOptionsHandler.Process(ProtocolContext context)&lt;/p&gt;  &lt;p&gt;&amp;#160;&amp;#160; at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Resolution:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;Install:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Visual C++ Redistributable x64 and x86 (&lt;a href=&quot;https://www.microsoft.com/en-us/download/details.aspx?id=49984&quot;&gt;https://www.microsoft.com/en-us/download/details.aspx?id=49984&lt;/a&gt; )&lt;/li&gt;    &lt;li&gt;KB2919355 installed If you are using Windows Server 2012R2 (&lt;a href=&quot;https://support.microsoft.com/en-us/kb/2919355)&quot;&gt;https://support.microsoft.com/en-us/kb/2919355)&lt;/a&gt;       &lt;br /&gt;&lt;/li&gt; &lt;/ol&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/04/azure-mfa-adfs-adaptor-and.html</link><author>noreply@blogger.com (Blog-5)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-7133217498844667416</guid><pubDate>Tue, 09 Feb 2016 20:00:00 +0000</pubDate><atom:updated>2016-05-12T16:52:45.970-05:00</atom:updated><title>Azure Authenticator–Unable to add the account</title><description>&lt;p&gt;&lt;strong&gt;Error:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;During activation &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/multi-factor-authentication-azure-authenticator/&quot; target=&quot;_blank&quot;&gt;Azure Authenticator application&lt;/a&gt; generates the following error message on Android device. This URL and code works on Apple and Microsoft mobile devices.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Unable to add the account.&amp;#160; We couldn’t add the account as your device does not trust the activation URL.&amp;#160; Please contact your IT administrator&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMzvTIWmCEpm-OeeZq-EPW14rPcVPmLzICLh8iljp8iXuao3pAZgWEvOq1Sl1aLn4tgKZKlL6cwGJEy_m-H-qJ2-B7OrhsMbif0-YiR2TTEtlpSdMXHJNDe0uldjZ5ly1-V3ZB_P158nE/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; display: inline; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi73uu7lIbj1b81p4SvMkXG16I380zw8S1KpzR5EKelT3YbbrYIHVLmunElU0GV5Hf6BTq9du17nONtLtTNL4whxQZj-Z1bHNUYokoiSqAl_JHDBpvpq_vAnlCivMJQiPTGYJARPWoaXs0/?imgmax=800&quot; width=&quot;399&quot; height=&quot;505&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Troubleshooting steps:&lt;/strong&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Try to activate the account using Apple or Microsoft device&lt;/li&gt;    &lt;li&gt;Verify the URL publishing configuration.&amp;#160; Are you publishing the Microsoft MFA Mobile App using Windows Application Proxy? &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;Solution / Workaround:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The issue is not really related to MFA or certificate configuration.&amp;#160; The issues is more related to how you publish the Mobile App URL to the internet.&amp;#160;&amp;#160; If you are using Web Application Proxy for publishing the URL (&lt;a title=&quot;http://portal.sivarajan.com/2016/01/azure-mfapublish-mfa-portals-using-web.html&quot; href=&quot;http://portal.sivarajan.com/2016/01/azure-mfapublish-mfa-portals-using-web.html&quot;&gt;http://portal.sivarajan.com/2016/01/azure-mfapublish-mfa-portals-using-web.html&lt;/a&gt;), there is an issue with&amp;#160; &lt;a href=&quot;https://blogs.technet.microsoft.com/applicationproxyblog/2014/06/19/how-to-support-non-sni-capable-clients-with-web-application-proxy-and-ad-fs-2012-r2/&quot; target=&quot;_blank&quot;&gt;Server Name Indication (SNI) certifies and Android devices&lt;/a&gt;. You can try one of the workaround mentioned in that article. &lt;/p&gt;  &lt;p&gt;Other option is to publish the Mobile app URL using some other method as mentioned here - &lt;a title=&quot;http://portal.sivarajan.com/2016/01/azure-mfapublish-mfa-portals-using-web.html&quot; href=&quot;http://portal.sivarajan.com/2016/01/azure-mfapublish-mfa-portals-using-web.html&quot;&gt;http://portal.sivarajan.com/2016/01/azure-mfapublish-mfa-portals-using-web.html&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/02/azure-authenticatorunable-to-add-account.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi73uu7lIbj1b81p4SvMkXG16I380zw8S1KpzR5EKelT3YbbrYIHVLmunElU0GV5Hf6BTq9du17nONtLtTNL4whxQZj-Z1bHNUYokoiSqAl_JHDBpvpq_vAnlCivMJQiPTGYJARPWoaXs0/s72-c?imgmax=800" height="72" width="72"/><thr:total>15</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1348925442188152640</guid><pubDate>Tue, 12 Jan 2016 08:00:00 +0000</pubDate><atom:updated>2016-05-26T11:59:02.427-05:00</atom:updated><title>SharePoint 2013 Products Preparation Tool–Stuck in Configuration Application Server Role, Web Server (IIS) Role</title><description>&lt;p&gt;&lt;strong&gt;Issue:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;SharePoint 2013 Products Preparation Tools stuck during the “Now Installing Prerequisites” stage with Configuration Application Server Role.&amp;#160; web Server (IIS) Role as show below:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi40gaTNKq2wuYCegDBxjFzEX9NgQbdKDlhculLipQ7Ubk0CnxtobViyQ48qft2p3EvVyJtDQWxn5UFtUOCF5BhC1aHTMNM5iK2YYBF3NZpPZwUqViJmfPavLDE_aotOUj4R6rSZIUqVBU/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNrOGlxrLRSsIqKnKixlURGgpbSUTDgoP5yVH4q5JAi9PL9uiJ7Yw4fXhq8gMFHlc3mznTveegGjJCZhO5AujeHy7fqGsqXfCJRrTb8qEu7A_dPhU9bimQazKGzbBv02MsItzMOIZbwXI/?imgmax=800&quot; width=&quot;628&quot; height=&quot;507&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Solution / Workaround&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The Server Manger is causing the issue here.&amp;#160; Make sure Server Manger is not running in the background.&amp;#160; Closing Server Manager application will complete the pre-requisite installation successfully.&amp;#160;&amp;#160; &lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/01/sharepoint-2013-products-preparation.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNrOGlxrLRSsIqKnKixlURGgpbSUTDgoP5yVH4q5JAi9PL9uiJ7Yw4fXhq8gMFHlc3mznTveegGjJCZhO5AujeHy7fqGsqXfCJRrTb8qEu7A_dPhU9bimQazKGzbBv02MsItzMOIZbwXI/s72-c?imgmax=800" height="72" width="72"/><thr:total>9</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-899087813352255260</guid><pubDate>Thu, 07 Jan 2016 14:00:00 +0000</pubDate><atom:updated>2016-01-13T07:11:10.652-06:00</atom:updated><title>Azure MFA–Publishing MFA Portals using Web Applicaion Proxy</title><description>&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;The goal is to publish on premises Microsoft Multi Factor Authentication (MFA) server portals using &lt;a href=&quot;https://technet.microsoft.com/en-us/library/dn584107.aspx&quot;&gt;Web Application Proxy Service&lt;/a&gt; (not &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/active-directory-application-proxy-enable/&quot;&gt;Azure Application Proxy&lt;/a&gt;!) The Microsoft MFA has the following 3 portals:&lt;/p&gt;  &lt;p&gt;1. &lt;b&gt;User Portal -&lt;/b&gt; The User Portal section allows the administrator to install and configure the Multi-Factor Authentication User Portal.&lt;/p&gt;  &lt;p&gt;2. &lt;b&gt;Web Service SDK -&lt;/b&gt; The Web Service SDK section allows the administrator to install the Multi-Factor Authentication Web Service SDK. &lt;/p&gt;  &lt;p&gt;3. &lt;b&gt;Mobile App -&lt;/b&gt; The Mobile App section allows the administrator to configure settings for the Mobile App.&amp;#160; There is also a Mobile App Web Service which needs to be installed to support mobile app activations.&lt;/p&gt;  &lt;p&gt;At the end of the configuration, my goal is to provide a single direction URL for User Portal, Web Service SDK and Mobile App shown below: &lt;/p&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhY7Z1saGCC8K9ulfV4BPB5IANWNiZraboWIw_k74rb6MjWNqsz1qblrRZXhgzlFYa_uwVh0L1N0nySFxjhuzDgpfvOUwTka85Suz7DDAm_Ouf-pa-ZpKaE__PrBoIE5nLXQJLJNpzU38Y/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: none; padding-top: 0px; padding-left: 0px; margin: 0px auto 4px; display: block; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBgk7wlq4E6p4V7eqEgxZkUm3M6XBzTJAJZEwehqPRLTqyA3OfcyKwJwZ5vWdg82dkVFqpcb2DJCee_9WiG84W-BoTmG7rmLOyeAX2ghWQIpx1n6Y2p2E3AVCQ5xAcUibOeLlxUlJfH-I/?imgmax=800&quot; width=&quot;1108&quot; height=&quot;535&quot; /&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/01/azure-mfapublish-mfa-portals-using-web.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBgk7wlq4E6p4V7eqEgxZkUm3M6XBzTJAJZEwehqPRLTqyA3OfcyKwJwZ5vWdg82dkVFqpcb2DJCee_9WiG84W-BoTmG7rmLOyeAX2ghWQIpx1n6Y2p2E3AVCQ5xAcUibOeLlxUlJfH-I/s72-c?imgmax=800" height="72" width="72"/><thr:total>13</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1559928985305425185</guid><pubDate>Tue, 05 Jan 2016 14:00:00 +0000</pubDate><atom:updated>2016-01-13T07:11:46.399-06:00</atom:updated><title>Azure–Add an Application from the Gallery</title><description>&lt;p&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;As shown below, you have the following three options when integrating an application in Azure (of course it is based on your application type).&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgD6iHNUd1_f1lBXw3vxKtUlSawtjkR1be8HD9gpE5XWlw6qFx1dqBe0KcsMIrrwI0nGK1dBvmnwR16nflkT777IJZSenX8v4ryC3WVmMGS30iosDWuigyUMQvaiNjTskJdpccqDm-G6ZE/s1600-h/image%25255B11%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: none; padding-top: 0px; padding-left: 0px; margin: 0px auto 4px; display: block; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidf_M9eKGNvBqCwcLAvalf-Fe5NoyhKZKBflu-YwogUQ3E3zrC3RZLdw2JsNlW37-fhdXVCMGu12LtuY1D0OT7r78qW1HJp8qTFu3808biAvBzR2-ARMWFpSpxjeMEUGa-9J9UbEyp7wo/?imgmax=800&quot; width=&quot;528&quot; height=&quot;283&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;When adding a Custom application from the Gallery, you supposed to see the following configuration screen for the application integration:&lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh67qJ3UsfyONF50XXLfuJsvbSreR04uLfpXaBet17RpN1A6yqI3vDCV2gYsOfm8nxaCtPL_NCuvUo-uyVxrCW4ohR-P23PKSpOH7EaGa7nio_vFyWrYRAW3vEDtHseYZJ2cf2NhJRE0tI/s1600-h/image%25255B15%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: none; padding-top: 0px; padding-left: 0px; margin: 0px auto 4px; display: block; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2ZYJBvfmc9eN0IdMNvrr2fy9T-NxrmaQt42EHwqEfPmXuNo9G2hl1Cwp7lgIvoOP3mJH-6XDvvZKOpnco6POnpl8gIjV93DqdtNnakEAS6IKn9zFz0PU95ewUDNV2foLaGeNSGbzis8o/?imgmax=800&quot; width=&quot;911&quot; height=&quot;615&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Custom application is part of the &lt;a href=&quot;http://www.microsoft.com/en-us/server-cloud/products/azure-active-directory/overview.aspx&quot;&gt;Azure AD Premium&lt;/a&gt; offering. If you don’t have a premium license,&amp;#160; instead of the above screen, you will see a link &lt;b&gt;Add an unlisted application your organization is using &lt;/b&gt;which points to the &lt;a href=&quot;https://azure.microsoft.com/en-us/documentation/articles/active-directory-saas-custom-apps/&quot;&gt;https://azure.microsoft.com/en-us/documentation/articles/active-directory-saas-custom-apps/&lt;/a&gt; URL as shown below: &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKF_130UkjKXBbrltW5vjTmAMbX7Cu9Szch9v1B4UxQ88ypR7RBQJxwxrppqojD2xBe-giawTJbjgaoPh6LBpVYICW86kWNgLyJ2zgIGyRBDy2s88VGE35vugCos5BBA3gdoxjE_1yKRE/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-left-width: 0px; border-right-width: 0px; background-image: none; border-bottom-width: 0px; float: none; padding-top: 0px; padding-left: 0px; margin: 0px auto 4px; display: block; padding-right: 0px; border-top-width: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGot4umv2TPamwRzzvuoSWgaZjfzA1tVuNKpcJei2Brow4lf4bFNq6JEo-NYdz-MSVdff2WFmSHqPw8Yt_Jqkzri-FfVDknnkPZuZO0kvWU1XDdrd9dHnOX1d9i9SfvhzLOQA0RoGX3OA/?imgmax=800&quot; width=&quot;913&quot; height=&quot;573&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This issue can be resolved by assigning the premium license to the respective Azure Directory. If you don’t have premium license, you can obtain a trial license from &lt;a href=&quot;https://azure.microsoft.com/en-us/trial/get-started-active-directory/&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/01/azureadd-application-from-gallery.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEidf_M9eKGNvBqCwcLAvalf-Fe5NoyhKZKBflu-YwogUQ3E3zrC3RZLdw2JsNlW37-fhdXVCMGu12LtuY1D0OT7r78qW1HJp8qTFu3808biAvBzR2-ARMWFpSpxjeMEUGa-9J9UbEyp7wo/s72-c?imgmax=800" height="72" width="72"/><thr:total>8</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-6939520029032683172.post-1093972254898015724</guid><pubDate>Mon, 04 Jan 2016 08:00:00 +0000</pubDate><atom:updated>2016-05-26T11:52:08.834-05:00</atom:updated><title>SharePoint 2013 Product Preparation tool–There was an error during installation</title><description>&lt;p&gt;&lt;strong&gt;Issue:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;The SharePoint 2013 Product Preparation tool failed with following error message: &lt;/p&gt;  &lt;p&gt;There was an error during installation.&amp;#160; The tool was unable to install application server Roles, Web Server (IIS) Roles.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZPef0ojDqbXOS96tVypD0Fvjc5_SQHk7b0PaVPCIbrFX-KltmG23TYDc83DG92E-NzMCfvagq52LyBFO62jrkfIGoI5lzk3sApAbspFmeROWaViedpm_tpXHsUNxpRt75M2j2BhuKPzA/s1600-h/image%25255B3%25255D.png&quot;&gt;&lt;img title=&quot;image&quot; style=&quot;border-top: 0px; border-right: 0px; background-image: none; border-bottom: 0px; padding-top: 0px; padding-left: 0px; margin: 0px 4px 4px 0px; border-left: 0px; display: inline; padding-right: 0px&quot; border=&quot;0&quot; alt=&quot;image&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSavNT6ncIWghGfQn14s5SIN3QX9bMtgaKU-rYQUqllEtBr3Nexfamqb_0dRdcVshUtWYOJmh0a3aLLXzovUxazGorbWFwu6vDJzeu90OZ4dnQB4qzVgCJM1gIU4AA7DAB83DV_sbqRjA/?imgmax=800&quot; width=&quot;748&quot; height=&quot;568&quot; /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Solution:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;a title=&quot;https://support.microsoft.com/en-us/kb/2765260&quot; href=&quot;https://support.microsoft.com/en-us/kb/2765260&quot;&gt;https://support.microsoft.com/en-us/kb/2765260&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Workaround:&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;By default, the installation process is looking for ServerManagerCMD.exe to execute these task.&amp;#160; Verify that the ServerManagerCMD.exe exist in C:\Windows\System32\ folder.&amp;#160; The ServerManagerCMD.exe command is available only on servers that are running Windows Server 2008 or Windows Server 2008 R2. The Servermanagercmd.exe command has been deprecated, and is not available in Windows Server 2012.&amp;#160; Recommended option is to use &lt;a href=&quot;https://technet.microsoft.com/en-us/library/cc731774.aspx&quot; target=&quot;_blank&quot;&gt;Windows PowerShell cmdlets&lt;/a&gt;.&amp;#160; In Windows Server 2012, ServerManager.exe file exist in C:\Windows\System32\ folder.&amp;#160; As a workaround, you can copy the ServerManager.exe to ServerManagerCMD.exe to complete the pre-requisite installation.&amp;#160; &lt;/p&gt;  &lt;p&gt;Addition info:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;a title=&quot;https://support.microsoft.com/en-us/kb/2765260&quot; href=&quot;https://support.microsoft.com/en-us/kb/2765260&quot;&gt;https://support.microsoft.com/en-us/kb/2765260&lt;/a&gt;&lt;/li&gt;    &lt;li&gt;&lt;a title=&quot;https://technet.microsoft.com/en-us/library/ff686793.aspx&quot; href=&quot;https://technet.microsoft.com/en-us/library/ff686793.aspx&quot;&gt;https://technet.microsoft.com/en-us/library/ff686793.aspx&lt;/a&gt;&lt;/li&gt; &lt;/ol&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;http://www.amazon.com/dp/1849687447/?tag=packtpubli-20&lt;/div&gt;</description><link>http://santhoshsivarajan.blogspot.com/2016/01/sharepoint-2013-product-preparation.html</link><author>noreply@blogger.com (Blog-5)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSavNT6ncIWghGfQn14s5SIN3QX9bMtgaKU-rYQUqllEtBr3Nexfamqb_0dRdcVshUtWYOJmh0a3aLLXzovUxazGorbWFwu6vDJzeu90OZ4dnQB4qzVgCJM1gIU4AA7DAB83DV_sbqRjA/s72-c?imgmax=800" height="72" width="72"/><thr:total>10</thr:total></item></channel></rss>