A company wants to enforce MFA for VPN users but allow users to authenticate without MFA when connecting from the corporate office. Which authentication policy configuration achieves this?
Trap 1: Disable MFA in the global Authentication Profile
Disabling MFA in the global Authentication Profile removes the MFA challenge for every user regardless of source address, so VPN users connecting from outside the office also authenticate without a second factor. A global profile is the correct place to turn MFA off only when no user population should ever be challenged.
Trap 2: Create an authentication policy with source zone 'Corporate' set to…
This would require MFA even from corporate office, not desired.
Trap 3: Create an authentication policy with source zone 'Corporate' set to…
This would skip authentication entirely for corporate traffic, not just MFA.
- A
Disable MFA in the global Authentication Profile
Why it fails: Disabling MFA in the global Authentication Profile removes the MFA challenge for every user regardless of source address, so VPN users connecting from outside the office also authenticate without a second factor. A global profile is the correct place to turn MFA off only when no user population should ever be challenged.
- B
Create an authentication policy with source zone 'Corporate' set to 'require MFA'
Why it fails: This would require MFA even from corporate office, not desired.
- C
Create an authentication policy with source zone 'Corporate' set to 'allow' and authentication method 'no MFA'
This allows authentication without MFA from the corporate zone.
- D
Create an authentication policy with source zone 'Corporate' set to 'no-auth' and action 'allow'
Why it fails: This would skip authentication entirely for corporate traffic, not just MFA.