Hello.
We enabled OTP for some users for userportal, SSL and IPSec VPN. The user has to login to the user portal the first time and scan the automatically generated QR code.
Thought, every user in the OTP list needs to activate its OTP to use VPN. But it seems the users can use VPN forward with their "normal credentials" without OTP because they just do not login to userportal so their QR code won't be generated. Is that right that users could login to VPN further without OTP until they login to user portal first time? And if so, could we "block this" in some way to force users to login and generate their code?
Thanks.
This thread was automatically locked due to age.