Hi,
We currently have ASA's & FTD's available for RA and use Secure Client, for auth we use certificates issued by our internal CA (user and devices for different profiles), however while this solution works really well I cant help but think is it as secure as it can be? for example if an employee leaves they can still VPN into the org which is a concern (unless we revoke the cert).remote
- We are Azure hybrid-AD, with more licenses available than i are care to count (so licenses shouldnt be an issue)
- We also have Cisco ISE internally
- workstations have TPM's
- Fairly sure we have Secure Client Premier License
I dont want users to be prompted for MFA each time they connect as it should be seamless and invisible to the end user.
Bassed on this can you provide any recommendations please.