Two factor authentication w/AD - specify field other than "Description" for the 2FA serial # CW#7572176
Partner is using AD authentication and would like to specify a different field in AD besides Description for the system to check/pull the 2FA serial number for validation. He uses Description for other things in AD and said he cannot append these details at the end as it may break some other things in the environment.
He also does not want to use LDAP as he has a multi-domain environment that doesn't work with LDAP.
We're looking to use 2FA as well and this is holding us back from implementing until we can find another way to store this information. The description field in AD makes no sense as a place to store this information. Can someone look at this request again to see if this can be changed or at lease offer an explanation as to why it cannot?
This field can be customized by setting up the LDAP user source method instead of Active Directory:
https://help.screenconnect.com/Windows_Active_Directory_and_LDAP_authentication#LDAP
Specifically, you would specify it under the UserPasswordQuestionAttribute field.