Your own ID-Server
On premise installations of SecSign ID offer the flexibility to connect with your preferred servers, services, and devices. And you can customize the SecSign ID with your own organization’s branding.
Learn MoreActive Directory Federation Services are used for local user management (for example Active Directory or LDAP) in companies for the authentication of web and cloud services (for example Office 365). But with added convenience comes an increase in security threats. Just one insufficiently secured user account is enough to give attackers access to an immense amount of sensitive company data.
Use your local Active Directory for authentication at cloud services and secure access with our SecSign ID on-premise Two-Factor Authentication server.
The authentication is redirected via the Active Directory, secured with the on-premise SecSign ID server. The authentication takes place on the local SecSign ID server.
That way all user can be managed and controlled local in the Active Directory. No sensitive data is ever transmitted to the cloud service.
Try the Login with the ADFS in our test environment.
This article gives an overview of securing your Office 365 Login with two-factor authentication. For a detailed tutorial on how to integrate two-factor authentication with your Office 365 Login, have a look at the plugin tutorial.
Introducing SecSign ID for Office 365 logins.
Protect access with our simple touch authentication and intuitive authentication rules, defined by you.
Compliance can easily be enforced and attacks to your company logins are rendered impossible.
The following video gives an overview on the authentication process. The complex process can easily be integrated in a few simple steps.
Try the secure Two-Factor Authentication for the Office 365 login. You can experience the functionalities in our test environment with your SecSign ID.
Contact us for the pluginWith the SecSign ID Two-Factor Authentication the user can log in to Office 365 in just one convenient and quick step – without inconvenient and complex codes.
To login the user simply needs to provide user credentials like he is used to, and select the displayed symbol in his mobile app – that’s it. Next level security with minimal complexity.
If required you can choose mobile or Email OTP (one-time passwords) as alternative authentication option.
With SecSign enrollment of your users is quick and convenient for both the user and the administrator.
You have several options to enroll your users for 2FA with SecSign. Most commonly, the 2FA ID should be identical to the Windows user name (for example sAMAccountName or userPrincipalName), and only successfully authenticated (user name and password) users should be able to create a 2FA account.
SecSign offers several options to achieve a default 2FA activation and link of the 2FA with the AD user. The two most popular are described below.
With Schema Extension to add a 2FA attribute to the user in the Active Directory, or without Schema Extension and read-only access from the SecSign ID Server.
For both options the enrollment procedure can either proceed via the Custom ID App or a custom landing page for the users to enroll.
An overview on how the Active Directory can be integrated with you 2FA setup is available here.
All Windows Plugins are available as a MSI for a convenient and quick install
Common steps for the integration with Microsoft Office 365 are explained here:
1 On the Windows Server run the Server Manager, Add Roles and Features. Please check the following options additionally to those selected per default already:
2 Promote the server to a domain controller if not done already.
3 Install a recent Oracle Java run time enviroment from: https://java.com/
4 Add the SecSign ID user attribute to the Active Directory: https://www.secsign.com/two-factor-authentication-in-active-directory/
5 Import a certificate for HTTPS on the Windows Server.
6 Install the imported certificate for HTTPS at the Web Server (IIS).
7 Sign up for a free trial (or a paid subscription) of Microsoft Office 365 at: https://products.office.com/en-us/business/office-365-business-premium
8 Install “Microsoft Azure Active Directory Connect” from: http://www.microsoft.com/en-us/download/details.aspx?id=47594
9 Install “Active Directory module for Windows Powershell”. (On a domain controller this is installed already.)
10 Install “Azure Active Directory Connection” from: http://connect.microsoft.com/site1164/Downloads/DownloadDetails.aspx?DownloadID=59185 and download & install AdministrationConfig-V1.1.166.0-GA.msi
11 Install SecSign ID Federation SAML generator.
12 Configure the federation properties by running these commands in a Powershell:
$Domain = “
$ActiveLogOnUri = “https://
$FederationBrandName = “SecSign”
$IssuerUri = “https://
$LogOffUri = “https://
$MetadataExchangeUri = “https://
$PassiveLogOnUri = “https://
Set-MsolDomainAuthentication –DomainName $Domain -IssuerUri $IssuerUri -LogOffUri $LogOffUri -PassiveLogOnUri $PassiveLogOnUri -ActiveLogOnUri $ActiveLogOnUri -FederationBrandName $FederationBrandName -MetadataExchangeUri $MetadataExchangeUri -SigningCertificate $SECSIGNSAMLSIGNCERT -Authentication Federated
Remove-MsolUser –UserPrincipalName
More details here:
https://support.microsoft.com/en-us/kb/2709902
For more information about the individual Windows Plugins select your user case below.
On premise installations of SecSign ID offer the flexibility to connect with your preferred servers, services, and devices. And you can customize the SecSign ID with your own organization’s branding.
Learn MoreWe are happy to announce that the SecSign ID server has passed the official FIDO certification program of the FIDO Alliance. This will allow you to use the complete FIDO2/WebAuthn standard for passwordless 2FA sign-ins in your exi ...
Mehr LesenThe FIDO2 Project is a set of standards developed by the FIDO Alliance and the World Wide Web Consortium (W3C) to create a strong authentication protocol for the web. It consist mainly of the WebAuth standard for the browser part ...
Mehr LesenIn the recent weeks, home office work has increased potentially. And while employees are practicing social distancing from their home computer, attackers are working hard to exploit security issues in this situation that is unfami ...
Mehr LesenWant to learn more about SecSign’s innovative and highly secure
solutions for protecting your user accounts and sensitive data?
Use our contact form to submit your information, and a SecSign sales representative will contact you within one business day.
If you need assistance with an existing SecSign account or product
installation, please see the FAQs for more information on the most common questions. You don’t find the solution to your problem? Don’t hesitate to contact the
Product Support
I am Interested in