Jump to content

Recommended Posts

Posted

Hello, We use Sophos XG and our Windows clients happily authenticate using STAS. Does anyone know if this works or another SSO possibility exists for macOS? I have also tried pushing the Client Authentication Agent to macOS and having it start but this does not seem to have any sort of SSO and users need to authenticate maually here?

Very interested to hear how others have resolved or worked around this scenario?

Nick

Posted
You could pass the login credentials to RADIUS and use that for SSO. Its not pretty but its proved pretty solid for mobile devices; user logs in using normal credentials to the WiFi SSID which gets sent to Windows NPAS sitting on a DC which then uses the SophosXG as the accounting server.
Posted
Thanks, will certainly think about that but ideally I want to just pass the AD login along. I think the native macOS AD client does not work like a windows box.
Posted
Stas detects logins via the ad server audit logs so if the Macs are authenticating to AD they might still get picked up

 

That’s how we have ours setup with 150 shared iMacs, works. Although our stas is flakey at best, so looking for alternatives.

Posted
That’s how we have ours setup with 150 shared iMacs, works. Although our stas is flakey at best, so looking for alternatives.

 

Yeah I'll admit stas isn't terribly reliable and the login / logoff detection isn't great. I've had users signed in where its still got restrictions based on the previous user. RADIUS I've found to be much more reliable.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...