Product manual

4
1. Overview
ESET Secure Authentication (ESA) adds Two Factor Authentication (2FA) to Microsoft Active Directory domains. The ESA product
consists of the following components:
The ESA Web Application plugin, which provides 2FA to various Microsoft Web Applications.
The ESA Remote Desktop plugin, which provides 2FA for the Remote Desktop Protocol.
The ESA RADIUS Server, which adds 2FA to VPN authentication.
The ESA Authentication Service, which includes a REST-based API which can be used to add 2FA to custom applications.
ESA Management Tools:
o ESA User Management plug-in for Active Directory Users and Computers (ADUC), which is used to perform user management.
o ESA Management Console, which is used to configure ESA.
ESA requires Active Directory infrastructure since it stores its data in the Active Directory data store. This means that there is no
need for additional backup policies since the ESA data is automatically included in your Active Directory backups.
2. Requirements
Installing ESET Secure Authentication requires an Active Directory domain. The minimum supported Active Directory domain
functional level is "Windows 2000 Native".
The installer always automatically selects the Authentication Service and Management Tools components. Should the user select
a component that cannot be installed, the installer will inform them of the exact prerequisites that are outstanding.
2.1 Supported Operating Systems
ESET Secure Authentication Services and Management Tools have been tested and are supported on the following operating
systems:
Windows Server 2003 (both 32-bit and 64-bit)
Windows Server 2003 R2 (both 32-bit and 64-bit)
Windows Server 2008 (both 32-bit and 64-bit)
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Small Business Server 2008
Windows Small Business Server 2011
Windows Server 2012 Essentials
Windows Server 2012 R2 Essentials
The Management Tools are also supported on client operating systems from Windows XP SP3 and later, in both 32-bit and 64-bit
versions.
NOTE: When you install a RADIUS Server on Windows Small Business Server 2008 or 2011, the default NPS port must be changed
from 1812 to 1645. Verify that there are no processes listening on port 1812 before installing ESA by running the following
command: C:\> netstat -a -p udp | more