<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Hello certificate-based authentication for SAS94 in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937228#M28780</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/440477"&gt;@Acf2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows Hello is just a MFA/Single Sign-On system in the Windows ecosystem, for your client machines.&lt;/P&gt;
&lt;P&gt;In SAS 9.4, the main and supported SSO method (specially on windows) is Kerberos/IWA/NTLM.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since Kerberos is a requirement in Windows Hello, for as long as you configure Kerberos/IWA in SAS, SAS will have no trouble with the Authentication Method in your clients machines. The servers on Windows and SAS are able to pickup the Kerberos TGT ticket.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/on-premises-cert-trust" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/on-premises-cert-trust&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jul 2024 11:06:42 GMT</pubDate>
    <dc:creator>JuanS_OCS</dc:creator>
    <dc:date>2024-07-26T11:06:42Z</dc:date>
    <item>
      <title>Windows Hello certificate-based authentication for SAS94</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937151#M28768</link>
      <description>&lt;P&gt;Our organisation wants to replace Active Directory domain userid and password with Windows Hello. Can the SAS94 authentication provider on Windows Server 2019 be configured for Single Signon using the with this mechanism?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Some concepts here :&amp;nbsp;&lt;A href="https://www.microsoft.com/insidetrack/blog/implementing-strong-user-authentication-with-windows-hello-for-business/" target="_blank"&gt;Implementing strong user authentication with Windows Hello for Business (microsoft.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 16:55:24 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937151#M28768</guid>
      <dc:creator>Acf2</dc:creator>
      <dc:date>2024-07-25T16:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Hello certificate-based authentication for SAS94</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937175#M28775</link>
      <description>&lt;P&gt;This looks to me like a form of two-factor authentication. If this is just another step to getting you logged onto your computer via an AD account then SAS should be fine. If you no longer have an AD account, then this is absolutely problematic.&amp;nbsp;You need to have an Active Directory account to connect to remote SAS servers for example.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 23:38:45 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937175#M28775</guid>
      <dc:creator>SASKiwi</dc:creator>
      <dc:date>2024-07-25T23:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Hello certificate-based authentication for SAS94</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937228#M28780</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/440477"&gt;@Acf2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows Hello is just a MFA/Single Sign-On system in the Windows ecosystem, for your client machines.&lt;/P&gt;
&lt;P&gt;In SAS 9.4, the main and supported SSO method (specially on windows) is Kerberos/IWA/NTLM.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since Kerberos is a requirement in Windows Hello, for as long as you configure Kerberos/IWA in SAS, SAS will have no trouble with the Authentication Method in your clients machines. The servers on Windows and SAS are able to pickup the Kerberos TGT ticket.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/on-premises-cert-trust" target="_blank"&gt;https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/on-premises-cert-trust&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 11:06:42 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937228#M28780</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2024-07-26T11:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Hello certificate-based authentication for SAS94</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937241#M28781</link>
      <description>Thanks for the response. It looked like it was possible and I hope my organisation is prepared to support Kerberos/IWA/NTLM. For once, there is some budget....</description>
      <pubDate>Fri, 26 Jul 2024 12:51:06 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937241#M28781</guid>
      <dc:creator>Acf2</dc:creator>
      <dc:date>2024-07-26T12:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Hello certificate-based authentication for SAS94</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937245#M28783</link>
      <description>&lt;P&gt;Thanks.&lt;BR /&gt;I have been asked for an initial assessment and don't have many details yet. Since a lot of workload is moving from on-prem servers to Azure, I am assuming Azure Active Directory will replace our local domain controllers. SAS94 will stay local for at least the next 2 years.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 13:02:11 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Windows-Hello-certificate-based-authentication-for-SAS94/m-p/937245#M28783</guid>
      <dc:creator>Acf2</dc:creator>
      <dc:date>2024-07-26T13:02:11Z</dc:date>
    </item>
  </channel>
</rss>

