<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC Admin login with MFA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5151318#M1114653</link>
    <description>&lt;P&gt;We have successfully tested SSO with MFA logon to the FMC. However, when we attempt to logout, we receive the following message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You are logged in using SSO provided by Azure. To protect your Firewall Management Center account from unauthorized access, you must separately end your Azure IdP session.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;There is a button labeled "Redirect to Azure for Log Out."&lt;/P&gt;&lt;P&gt;Clicking that button redirects me to my MS 365 home page.&lt;/P&gt;&lt;P&gt;Subsequent logon attempts to the FMC allows me right into the console without 1st or 2nd factor authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that this is the basic premise for SSO...but I wanted to know if there was a way to terminate a session so that I am not allowed directly back into the console without being challenged.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Jul 2024 20:36:53 GMT</pubDate>
    <dc:creator>Danny Dulin</dc:creator>
    <dc:date>2024-07-25T20:36:53Z</dc:date>
    <item>
      <title>FMC Admin login with MFA</title>
      <link>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5151318#M1114653</link>
      <description>&lt;P&gt;We have successfully tested SSO with MFA logon to the FMC. However, when we attempt to logout, we receive the following message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You are logged in using SSO provided by Azure. To protect your Firewall Management Center account from unauthorized access, you must separately end your Azure IdP session.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;There is a button labeled "Redirect to Azure for Log Out."&lt;/P&gt;&lt;P&gt;Clicking that button redirects me to my MS 365 home page.&lt;/P&gt;&lt;P&gt;Subsequent logon attempts to the FMC allows me right into the console without 1st or 2nd factor authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that this is the basic premise for SSO...but I wanted to know if there was a way to terminate a session so that I am not allowed directly back into the console without being challenged.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 20:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5151318#M1114653</guid>
      <dc:creator>Danny Dulin</dc:creator>
      <dc:date>2024-07-25T20:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Admin login with MFA</title>
      <link>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5151328#M1114655</link>
      <description>&lt;P&gt;since you are using the browser you are bound by the M365 login already there... but there are some workarounds you can implement:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.reddit.com/r/AZURE/comments/xrupux/conditional_access_require_mfa_every_single_time/" target="_blank"&gt;https://www.reddit.com/r/AZURE/comments/xrupux/conditional_access_require_mfa_every_single_time/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/answers/questions/1107473/how-to-make-an-azure-enterprise-application-always" target="_blank"&gt;https://learn.microsoft.com/en-us/answers/questions/1107473/how-to-make-an-azure-enterprise-application-always&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 21:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5151328#M1114655</guid>
      <dc:creator>ccieexpert</dc:creator>
      <dc:date>2024-07-25T21:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Admin login with MFA</title>
      <link>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5167837#M1115498</link>
      <description>&lt;P&gt;Here is one workaround. where would I do this in FMC?&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I modified the machine sending the SAML request to use the ForceAuthn=true option which forced all users accessing an authentication portal to authenticate every time without making changes to the conditional access policy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 20:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-admin-login-with-mfa/m-p/5167837#M1115498</guid>
      <dc:creator>Danny Dulin</dc:creator>
      <dc:date>2024-08-29T20:15:26Z</dc:date>
    </item>
  </channel>
</rss>

