Skip to main content
Skip table of contents

Set up Nexus OTP as 2FA for Outlook Web Access

This article describes how to enable Nexus OTP in Smart ID Digital Access component as two-factor authentication method for Outlook Web Access using Microsoft ISA Server 2006, to replace static passwords.

Nexus OTP can be either Nexus TruID Synchronized or Smart ID Mobile App OTP, or any other OATH-based mobile OTP application, such as Google Authenticator or Microsoft Authenticator. 

With the setup described in this article, Digital Access functions as a RADIUS server and Microsoft ISA Server 2006 as a RADIUS client. Nexus TruID is used as an example below and is available for iOS, Android, and Windows.

Network schematic for Nexus OTP authentication

Network schematic with Nexus TruID Synchronized as an example.

  1. The end user starts the TruID client and enters the PIN in TruID to generate an OTP.
  2. Outlook Web Access request the end user to enter username, password and OTP.
  3. The end user enters username, domain password and OTP.
  4. The domain credentials are validated by the Active Directory through Outlook Web Access.
  5. The OTP authentication request is relayed to Digital Access Authentication Server via RADIUS by Microsoft ISA Server 2006.
  6. The authentication server validates the OTP with the associated TruID token and PIN from the user database.
  7. Upon successful validation, the authentication server responds with successful authentication to Microsoft ISA Server 2006.

Microsoft ISA Server 2006 and Outlook Web Access provides access to the end user.


Make settings in Digital Access

Log in to Digital Access Admin
  1. Log in to Digital Access Admin with an administrator account.
Add Microsoft ISA Server 2006 as a RADIUS client

In step 3, enter the IP Address of the RADIUS Client (Microsoft ISA Server) and the Shared Secret Key.

  1. In Digital Access Admin, go to Manage System.
  2. Click RADIUS Configuration > Add RADIUS Client...
  3. Enter General Settings and Attributes. Click the ?-sign for help.
  4. Click Save.
Enable authentication method

Nexus TruID Synchronized is used as an example. Other Nexus OTP authentication methods are enabled in a similar way.

  • In step 3, select Nexus Synchronized as method.
  • When the default RADIUS replies are shown, click Next. You can also add your custom RADIUS replies or modify the default replies if required.

To add a new authentication method:

  1. In Digital Access Admin, go to Manage System.
  2. Click Authentication Methods.
  3. Click Add authentication method..., select the desired method and click Next.

  4. Enter Display Name, a unique name used in the system to identify the authentication method.
  5. Select if the method shall be enabled and if it shall be visible in authentication menu.
  6. Register Authentication Methods Server when applicable.
  7. Make other configurations as needed for the selected authentication method. For more information , click the ?-sign. Click Next.
  8. If needed, make settings in RADIUS Replies and Extended Properties.
  9. Click Next and Finish.
  10. Click Publish.

Make settings in Microsoft ISA Server 2006

Add Digital Access as RADIUS Server
  1. Log in to the Microsoft ISA Server 2006 server and open the administration console.
  2. Check Collect additional delegation credentials in the form.
  3. Select RADIUS OTP.
  4. Click Configure Validation Servers.

  5. Click Add in the RADIUS Servers tab.

  6. Configure the RADIUS server’s details (Server name, Shared secret, Authentication port, Time-out) in the Add RADIUS Server pop up. Click OK to apply the changes.

  7. In the Users tab, select the user groups that this rule should apply to. In this example, the All Users group was selected.

  8. Click Next.

Example: Log in to Outlook Web Access

Example: Use Nexus TruID as 2FA to log in to Outlook Web Access
  1. Start Nexus TruID that is installed on your laptop or smartphone - Enter your PIN to generate an OTP.

  2. Start the web browser and browse to Outlook Web Access.

  3. Enter logon credentials in the Outlook Web Access logon page:

    1. AD UserID in the User Name field.

    2. The OTP from TruID Synchronzed in the Passcode field.

    3. AD Password in the Password field.

  4. Click Log On.

Related information

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.