MFA for Entra Account in ZTNA Admin Console
search cancel

MFA for Entra Account in ZTNA Admin Console

book

Article ID: 443270

calendar_today

Updated On:

Products

Symantec ZTNA

Issue/Introduction

Organizations leveraging Microsoft Entra ID for identity management within Symantec ZTNA often require elevated security controls for administrative access. Specifically, the goal is to enforce Multi-Factor Authentication (MFA) exclusively for the ZTNA Admin Console without disrupting standard users or breaking automated access to specific Web Apps.

When MFA is enabled on the primary ZTNA app registration in Entra ID, it is triggered for all associated URIs (e.g., admin.example.luminatesec.com, example.luminatesec.com, and individual Web Apps), which can cause friction for non-admin users.

How can one separate ZTNA admin and non admin users for MFA requirements?

Environment

ZTNA Admin Console.

Enterprise Console.

Cause

Entra Enterprise Application is the same for admin/non admin users.

Resolution

A number of options exist, but the best is to simply use the Enterprise Console (https://enterprise.security.com) to administer ZTNA instead of the ZTNA Admin Console. This will be the ZTNA admin portal moving ahead with the current option going away.

The Enterprise Console will provide admins the ability to login to a SAML IdP provider defined for all Symantec Cloud service admins to use.

For those that want to remain on the ZTNA Portal for the short term:

  • Create a ZTNA admin group within the Entra setup
  • Define a conditional access policy for the ZTNA application so that users that are a member of the above ZTNA admin group do step up authentication to satisfy the MFA requirements