• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Company · Blog · Newsletter · Events · Partner Program

Downloads      Support      Security     Admin Login      Password Generator
Rublon

Rublon

Secure Remote Access

  • Product
    • Regulatory Compliance
    • Use Cases
    • Rublon Reviews
    • Authentication Basics
    • What is MFA?
    • User Experience
    • Authentication Methods
    • Rublon Authenticator
    • Remembered Devices
    • Logs
    • Single Sign-On
    • Access Policies
    • Directory Sync
  • Solutions
    • MFA for Remote Desktop
    • MFA for Remote Access Software
    • MFA for Windows Logon
    • MFA for Linux
    • MFA for On-Premise Active Directory
    • MFA for LDAP
    • MFA for RADIUS
    • MFA for SAML
    • MFA for RemoteApp
    • MFA for Workgroup Accounts
    • MFA for Entra ID
  • Customers
  • Industries
    • Financial Services
    • Investment Funds
    • Retail
    • Technology
    • Healthcare
    • Legal
    • Education
    • Government
    • Utilities
  • Pricing
  • Docs
Contact Sales Free Trial

Multi-Factor Authentication (2FA/MFA) for ManageEngine ADManager Plus

Multi-Factor (MFA) and Two-Factor Authentication (2FA) for ManageEngine ADManager Plus

November 27, 2025 By Rublon Authors

Last updated on December 8, 2025

Overview

Rublon Multi-Factor Authentication (MFA) for ManageEngine ADManager Plus adds an extra layer of protection, ensuring that only authorized users can access the system. ADManager Plus MFA enforces both primary authentication (username and password) and a secondary method, such as Mobile Push, to ensure that access is granted only to verified users through a layered security approach.

The purpose of this document is to enable Rublon Multi-Factor Authentication (MFA) for ManageEngine ADManager Plus logins. To achieve this using SAML, you have to use Rublon Access Gateway. All required steps will be described in this document.

Supported Authentication Methods

Authentication Method Supported Comments
Mobile Push ✔ N/A
FIDO ✔ N/A
Passcode ✔ N/A
SMS Passcode ✔ N/A
SMS Link ✔ N/A
Phone Call ✔ N/A
QR Code ✔ N/A
Email Link ✔ N/A
YubiKey OTP ✔ N/A
RFID – N/A

Before you start

Before configuring Rublon MFA for ADManager Plus:

  • Ensure you have prepared all required components.
  • Create an application in the Rublon Admin Console.
  • Install the Rublon Authenticator mobile app.

Required Components

1. User Identity Provider (IdP) – You need an external Identity Provider, such as Microsoft Active Directory, OpenLDAP, FreeIPA, FreeRADIUS, or Microsoft NPS.

2. Rublon Access Gateway – Install and configure Rublon Access Gateway itself before configuring ADManager Plus to work with it. Read the Rublon Access Gateway documentation and follow the steps in the Installation and Configuration sections. Afterward, continue with this document.

3. ADManager Plus – A properly installed and configured ManageEngine ADManager Plus.

Create an Application in the Rublon Admin Console

1. Sign up for the Rublon Admin Console. Here’s how.

2. In the Rublon Admin Console, go to the Applications tab and click Add Application. 

3. Enter a name for your application (e.g., ADManager Plus) and then set the type to Rublon Access Gateway.

4. Click Save to add the new application in the Rublon Admin Console.

5. Copy the values of System Token and Secret Key of the newly created application. You will need them later.

Install Rublon Authenticator

Some end-users may use the Rublon Authenticator mobile app. So, as a person configuring MFA for ADManager Plus, we highly recommend you install the Rublon Authenticator mobile app, too. Thanks to that, you will be able to test MFA for ADManager Plus via Mobile Push.

Download the Rublon Authenticator for:

  • Android
  • iOS
  • HarmonyOS

Configuration

1. To add MFA to ADManager Plus logins, you need one or more Help Desk Technicians. In the ADManager Plus Admin Panel, go to Delegation → Help Desk Technicians → Add New Technician, fill in the fields, and select Save. Refer to the following image and table.

A screenshot showing how to add a new Help Desk Technician in ADManager Plus during MFA for ADManager Plus configuration.
Select DomainSelect the same domain you set in the Authentication Sources tab of the Rublon Access Gateway.
Select AD Users / GroupsSelect the user.
Select Help Desk RolesSelect the user role.
Select OUsSelect All OUs.

2. In the Rublon Access Gateway, select Application → Import application metadata → DOWNLOAD XML METADATA. The .xml file will open in your browser. Right-click and save as metadata.xml. By default, the browser tries to save it as a .php file, so you need to change the extension to .xml.

A screenshot showing how to download the metadata file from the Rublon Access Gateway during MFA for ADManager Plus configuration.

3. In the ADManager Plus Admin Panel, go to Delegation → Configuration → Logon Settings → Single Sign On.

4. Check Enable Single Sign-on and select SAML Authentication.

5. In the SP Configuration section, select Modify.

A screenshot showing how to modify SSO settings during MFA for ADManager Plus configuration.

6. The SAML configuration window opens. Fill in the fields in the Configure Identity Provider section. Refer to the following image and table.

A screenshot showing how to fill out the Configure Identity Provider section during MFA for ADManager Plus configuration.
Identity Provider (Idp)Custom SAML
Idp Provider NameRublon
IdP Provider LogoSkip.
SAML Config ModeSelect Upload Metadata File and then select the metadata.xml you have previously downloaded from the Rublon Access Gateway.
Expand Advanced Settings.
SAML RequestSigned
Authentication Context ClassUnspecified
SAML ResponseSigned
SAML AssertionSigned
Signature AlgorithmSHA256
Assertion EncryptionEncrypted
Encryption CertificateSelf-Signed or CA-Signed, depending on the type of your certificate.
Single LogoutOptional. Enable this option to log out of all applications associated with the Rublon Access Gateway when you log out of ADManager Plus.

7. Navigate to the Service Provider (SP) Details section. In ACS/Recipient URL, enter the domain address and port used to connect to the ADManager Plus. Use a colon in between, e.g.,:

admanagerplus.rublon.com:1234

8. Navigate to the Mapping Attribute Selection section. In Mapping Attribute, select mail.

A screenshot showing how to fill out the Service Provider (SP) Details and Mapping Attribute Selection sections during MFA for ADManager Plus configuration.

9. Select Save to save your SAML configuration.

10. Back in the Single Sign On tab, select Download SP Metadata to download the sp_metadata.xml file. Then, open the file in a text editor and change the following values:

  • Set validUntil=“2026-11-27T10:01:11.009Z”
  • Set AuthnRequestsSigned=”true”
  • Set WantAssertionsSigned=”true”

Then, save the sp_metadata.xml file.

Note: ADManager Plus does not pass the settings from Advanced Settings to the sp_metadata.xml file, hence the need to make these adjustments.

A screenshot showing how to download the SP metadata file during multi-factor authentication for ADManager Plus configuration.

11. In the Rublon Access Gateway, go to Applications → Import application metadata, enter the name for your application (e.g., ADManager Plus), select the sp_metadata.xml file from your computer, and select UPLOAD. The application will appear on the applications list under the All applications subtab.

A screenshot showing how to upload the SP metadata file in the Rublon Access Gateway during multi-factor authentication for ADManager Plus configuration.

12. Your configuration is complete. You can now test logging in to ADManager Plus with Rublon Multi-Factor Authentication (MFA).

Testing Multi-Factor Authentication (MFA) for ADManager Plus Via SAML

1. On the ADManager Plus login page, click Rublon under the standard login form.

A screenshot showing that the user needs to click Rublon under the standard ADManager Plus login form to initiate Rublon MFA for ADManager Plus.

2. You will be redirected to the Rublon Access Gateway login page.

A screenshot showing the Rublon Access Gateway login form during MFA login to ADManager Plus.

3. Provide your username and password. Click SIGN IN. The Rublon Prompt will appear with a selection of various Rublon MFA options. Let’s choose Mobile Push.

4. Rublon MFA will send a Mobile Push authentication request to your phone. Tap APPROVE.

A screenshot showing the Mobile Push notification received by the user during MFA login to ADManager Plus.

5. You will be logged in to ADManager Plus.

Troubleshooting

If you encounter any issues with your Rublon MFA integration, please contact Rublon Support.

Related Posts

Rublon Access Gateway – Documentation

Rublon Access Gateway – Integrations

Filed Under: Documentation

Primary Sidebar

Contents

  • Overview
  • Supported Authentication Methods
  • Before you start
    • Required Components
    • Create an Application in the Rublon Admin Console
    • Install Rublon Authenticator
  • Configuration
  • Testing Multi-Factor Authentication (MFA) for ADManager Plus Via SAML
  • Troubleshooting
  • Related Posts
Try Rublon for Free
Start your 30-day Rublon Trial to secure your employees using multi-factor authentication.
No Credit Card Required
Rublon 5 star reviews on Gartner Peer Insights

Footer

Product

  • Regulatory Compliance
  • Use Cases
  • Rublon Reviews
  • Authentication Basics
  • What is MFA?
  • User Experience
  • Authentication Methods
  • Rublon Authenticator
  • Remembered Devices
  • Logs
  • Single Sign-On
  • Access Policies
  • Directory Sync

Solutions

  • MFA for Remote Desktop
  • MFA for Windows Logon
  • MFA for Remote Access Software
  • MFA for Linux
  • MFA for On-Premise Active Directory
  • MFA for LDAP
  • MFA for RADIUS
  • MFA for SAML
  • MFA for RemoteApp
  • MFA for Workgroup Accounts
  • MFA for Entra ID

Industries

  • Financial Services
  • Investment Funds
  • Retail
  • Technology
  • Healthcare
  • Legal
  • Education
  • Government
  • Utilities

Documentation

  • 2FA for Windows & RDP
  • 2FA for RDS
  • 2FA for RD Gateway
  • 2FA for RD Web Access
  • 2FA for SSH
  • 2FA for OpenVPN
  • 2FA for SonicWall VPN
  • 2FA for Cisco VPN
  • 2FA for Office 365

Support

  • Knowledge Base
  • FAQ
  • System Status

About

  • About Us
  • Blog
  • Events
  • Careers
  • Co-funded by the European Union
  • Contact Us

  • Facebook
  • GitHub
  • LinkedIn
  • Twitter
  • YouTube

© 2026 Rublon · Imprint · Legal & Privacy · Security

  • English
  • Polski (Polish)