Hi there,
I have installed a Cisco Firepower VPN gateway in my network which allows for users to connect remotely.
Unfortunately, after having logged in to the VPN by using the Anyconnect client (also using 2FA), the user has to log on again on Windows.
I know that there's a way to have single sign-on with the clientless vpn solution using the website, where the user's credentials are passed to the VPN client through the browser, but when using this, we will not be able to run login scripts nor do we get any Active Directory computer group policies downloaded to the client.
What we would need is:
- User starts Windows
- User selects the VPN logon symbol
- User logs on to the VPN
- User is automatically logged on to Windows
OR
- User clicks the Windows logon button and is automatically logged on without being asked for username and password again.
The Anyconnect client already "knows" the user's logon credentials, so there should be a way to forward them to Windows for its logon process...
Unfortunately, I did not find a way to get this done - only the other way around (as mentioned above), but this does not work in my environment due to the group policies and logon scripts.
Did anyone have the same issue?
Is there a fix for that?
Best
DiVineUser