This message was deleted.
# _general
s
This message was deleted.
👀 1
m
You might be better off doig it without a PRT. You can present the FAS cert using CBA and Entra to SSO to Office 365/microsoft
I’m doing that with a client that uses Duo and Azure AD
👀 1
d
I have an ongoing... discussion... with some folks about the "Allow in-session use" for FAS. Some... folks... are claiming it is a security risk and shouldn't be enabled. I always thought it was needed in these contexts. Glad to have come across this discussion and I'm curious about your results, @Jeff Riechers
m
Not sure how it’s a security risk
it’s basically just allowing you to do smartcard/certificate logon to other sites without having to generate a new cert for that
d
I don't see it as a risk either but you know how people are...
m
it’s not like you can take that cert and then log into anything with it, it’s only valid for logon to the machine it is on.
this 1
the real risk is access to the FAS servers themselves
d
Which this would not grant ;)
m
right. I have this enabled for a few clients now, it works pretty well unless you are doing multi domain stuff with Entra and don’t have all your domain suffixes in local AD too
In those cases you need to modify the template to include the email address, but sometimes even that isn’t enough
clients really should fix users upns, but you know how it be