Multi-Factor Authentication (VMware Verify)
This lab will be demonstrate how best to use multi-factor authentication to secure access the WorkspaceONE portal as well as various service providers
In this lab we will cover how to setup VMware Verify and then authenticate using a soft token.
Part 1: VMware Verify
Part 1: VMware Verify
- On the ConrolCenter2,
- Open Chrome and navigate to access.euc-livefire.com or select on the Access bookmark
- Select System Domain from the dropdown and
- Select Next.

- Authenticate using
- Username: admin
- Password: VMware1!
- Select Sign in
- In the Workspace ONE Access administration console
- Select on Identity & Access Management,
- Select on Authentication Methods
- Under Authentication Methods
- Select the pencil icon next to VMware Verify in the Authentication Methods page
- In the VMware Verify window
- Select the check box next to enable VMware Verify and then paste the following Security Token
eyJ2ZXJzaW9uIjoiMS4wIiwiYXBpS2V5IjoiZWZrTXVCY0lDaHdKcU5pTElTSlhjVWQwVnU1MG1RaGEiLCJhY2Nlc3NLZXkiOiJjQVhaa0lQajY2M2kyNmZ1YUJ2RVZVemNGZ2gzbU1pNDhiOXhPYm9CNnhrIiwiYXBwSWQiOiIyODY2MzciLCJhcHBBcGlLZXkiOiJDZVQxeXlvZnE1UFc4bGdFSUw3d3VrdWdHdHBsZENKdyIsInNpZ25pbmdLZXkiOiJQN0xEZ3Q4ajlEQ2k0N042a1hEMGVCRmFQck10WUVzOSIsImVuYWJsZWQiOnRydWV9
- Select Save at the bottom of the page
- In the Workspace ONE Access Console
- Navigate to Identity Provides at the top navigation tab.
- Select Built-in
- In the Built-in Identity Providers window
- Scroll down to the middle of the page until you see Authentication Methods,
- Select the checkbox next to VMware Verify
- Select Save at the bottom of the page
- We will add VMware verify to an access policy now
- In the Workspace ONE Access console
- Select Policies
- Select ADD POLICY
- In the Workspace ONE Access console

- On the New Access Policy Page
- Policy Name: Demo App
- Applies to: select the SAML Demo App from the drop down
- Select NEXT

- In the Configuration section
- Select ADD POLICY RULE

- In the Add Policy Rule windows select the following, next to:
- and user accessing content from: Web Browser
- then user may authenticate using (select from drop down): Password (Cloud deployment)
- To the right of Password (Cloud deployment) , select the "+" and from the dropdown, select VMware Verify
- Select SAVE at the bottom of the screen
- (leave the other settings as default)

- Back in the New Access Policy page
- Select NEXT

- On the Summary page of the New Access Policy window
- Select SAVE
- You should now have two access policies:
- The default access policy set and the Demo App policy.

- On your ControlCenter2 server
- Open your Mozilla Firefox browser or Chrome in incognito window.
- Navigate to the the Demo App on https://sptest.iamshowcase.com/ixs?idp=ad0afe77db012e758034028c0dc5e00ba60af514
- It will redirect to access.euc-livefire.com.
- Select Next with the euc-livefire.com domain selected

- In the Workspace ONE Access login
- Authenticate under
- username: user1
- password: VMware1!
- Select Sign in
- Authenticate under

- Now you will be redirected to authenticate using MFA. The first time this will require a phone number.
- In the Workspace ONE Login
- In the dropdown enter the Country Code
- Then put in your phone number and Select Sign In
- In the Workspace ONE Login
- On your mobile Phone
- Check that you received the information on how to sign up for VMware Verify on your mobile via SMS.
- Download the VMware Verify application
- Use the code in the message to authenticate to the app.

- On your Mobile Phone
- The process of installation may change according to your mobile platform (Above noted steps are for iOS).
- Follow the instructions in the VMware Verify application to enter your phone number

- On your Mobile Phone
- You will receive a SMS.
- Select on the link in the SMS message which will open the VMware Verify app
- Verify the application

-
On your Mobile Phone
- Set a new Pin code one the application for authentication
- Select Allow for push notification (This is optional)
- On your Mobile Phone
- Once the application has been configured you will now have the access.euc-livefire.com environment listed in the application for two-factor.

- On the Workspace ONE Access Login
- the code you see in the VMware Verify Application into the browser where VMware Verify is prompting you for the unique code.
- In the Workspace ONE Acces Console
- You should now be successfully authenticated to the SAML Demo App.
NOTE: SMS is only required for initial setup of the VMware Verify authentication method.
This concludes multi-factor using VMware Verify authentication lab.
Notice this authentication method is applied to a single application and does not apply to the default access policy.
0 Comments
Add your comment