Organizations leveraging Microsoft Entra ID for identity management within Symantec ZTNA often require elevated security controls for administrative access. Specifically, the goal is to enforce Multi-Factor Authentication (MFA) exclusively for the ZTNA Admin Console without disrupting standard users or breaking automated access to specific Web Apps.
When MFA is enabled on the primary ZTNA app registration in Entra ID, it is triggered for all associated URIs (e.g., admin.example.luminatesec.com, example.luminatesec.com, and individual Web Apps), which can cause friction for non-admin users.
How can one separate ZTNA admin and non admin users for MFA requirements?
ZTNA Admin Console.
Enterprise Console.
Entra Enterprise Application is the same for admin/non admin users.
A number of options exist, but the best is to simply use the Enterprise Console (https://enterprise.security.com) to administer ZTNA instead of the ZTNA Admin Console. This will be the ZTNA admin portal moving ahead with the current option going away.
The Enterprise Console will provide admins the ability to login to a SAML IdP provider defined for all Symantec Cloud service admins to use.
For those that want to remain on the ZTNA Portal for the short term: