How to add modern authentication to apps using NTLM over LDAP | Strata.io
Still using Active Directory to authenticate users? Secure your legacy mission-critical apps with a modern IDP instead — without refactoring.
Ingredients
- Modernize any app to Microsoft Entra ID using the Active Directory Authentication Facade.
- Add any modern services — like MFA — so your app meets current cybersecurity requirements.
- Create a single user access experience consistent with the rest of your apps.
- What the organization gains
- What the user sees
- What the admin does
- Comply with cybersecurity mandates. Using a modern IDP allows you to protect your app without rewriting it.
- Retire Active Directory from its authentication duties. The Maverics orchestrators sit on either side of your app. Instead of ‘talking’ to Active Directory, the app ‘talks’ to the orchestrators.
- Convenient failover. Your apps can fail over to Active Directory in case of emergency.
- Common login. Users now head to the same login screen as the rest of their apps, start the access workflow, and use their modern IDP for authentication.
- Invisible redirection. Behind the scenes, Maverics evaluates the app policy in the config and directs the user to your new modern IDP.
- Quick authentication. The user enters their IDP details, gets authenticated, and logs in. Everything in the app looks the same as before.
- Prepare your work surface. Define the upstream application and the port Maverics will use to communicate with the app.
- Set the rules. Define the basic policy that enforces authentication to your new modern IDP and define how Maverics will provide context to the upstream application.
- Configure. Set Maverics up as an authentication gateway and give it the right permissions to direct users correctly.
More Like This
How to extend Okta to any on-prem, legacy app | Strata.io
strata.io
How to add HYPR passwordless authentication | Strata.io
strata.io
Secure & control cross-border access to a global resource | Strata.io
strata.io
How to replace Keycloak with Amazon Cognito | Recipes | Strata.io
strata.io
Failover from Okta to on-prem Active Directory (AD) | Strata.io
strata.io
How to modernize off PingFed and PingAccess to Azure AD | Strata.io
strata.io
Claims Transformation - SAML and OIDC | Recipes | Strata.io
strata.io
Identity Orchestration Recipes - Strata.io
strata.io