At a very high level:
1. Ensure that Defender is passing windows domain group info (authorization info) in Radius attributes (as a part of access-accept packet)
2. On the SA select role mapping rules based on User attribute option.
For config help on # 1 you will have to check with the Radius vendor/documentation and for config help with #2 try the string 'Specifying Role Mapping Rules for an Authentication Realm' in the search option of the SA admin help interface (by clicking on help from the admin GUI)
Dear muttbarker
Thanks for this information and it was helpful to implement authentication with safeword SMS Auth. But now I have the challenge to change the messages for Challenge/Response to the right wording for SMS OTP.
I know the article for custom Sign-In pages, but I couldn't find the right files. What is the file name or where I could find information to change the messages?
Thanks
Dirk