Can i block SSL VPN if they don't have 2FA
Hi all,
We are in the process of ordering the mobile app and also the 200B physical 2FA for our SSL VPN users and i can see that i can pull the users across from LDAP and enable 2FA on there and then as long as they are in the VPN group on LDAP then this will work fine as currently it's just a case of being in the VPN group in Active Directory and they are allowed on but my question is that as you have to enable the 2FA for a user for it to work then if we don't enable it for a user but they are in the Active Directory group then will this bypass the 2FA and let them connect as normal or is there an option to say if they're in the group but don't use 2FA then don't allow the connection ?
Hope that makes sense.
Thanks
