---
title: "Setting Up Access Authentication"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35463193/Setting%20Up%20Access%20Authentication"
format: markdown
---
<span style="color: #000000">To set up automated security policy management using access authentication, do the following:</span>

1. <span style="color: #000000">Set up the IdP you plan to use and create applications and user group attributes in the IdP. Refer to the respective vendor documentation for details.</span>
2. <span style="color: #000000"> Review the prerequisites for using different protocols and IdPs. For more information, see </span>[*<span style="color: #000000">Prerequisites for Configuring Access Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35430215)<span style="color: #000000">.</span>
3. <span style="color: #000000">Create access authentication profiles that define the protocol and IdP you want to use. For more information, see </span>[*<span style="color: #000000">Configuring Authentication Profiles</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35462918)<span style="color: #000000">.</span>
4. <span style="color: #000000">Associate an authentication profile with the host on which you want to set up access authentication. For more information, see </span>*<span style="color: #000000">Associating Authentication Profiles with Hosts</span>*<span style="color: #000000">.</span>
5. <span style="color: #000000">Enable the access authentication and DNS forwarding proxy services on the host to which you want to apply security policies. For more information, see </span>*[<span style="color: #000000">Enabling and Disabling Services on Hosts</span>](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneInfrastructure/pages/184648009)*<span style="color: #000000">. </span>  
**<span style="color: #000000">Note that enabling the access authentication service might affect the existing DNS service. Contact Infoblox Technical Support for assistance in enabling the access authentication service. Once the service is enabled, all users will be redirected to the </span>*****<span style="color: #000000">Access Authentication</span>*****<span style="color: #000000"> page for authentication before any DNS resolution can happen.</span>**
6. <span style="color: #000000">Configure authentication settings if you want to </span><span style="color: #000000">modify the landing page of the captive portal </span><span style="color: #000000">for your users by presenting a login page that contains the required access authentication. For more information, see </span>[*<span style="color: #000000">Configuring Authentication Settings</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463149)<span style="color: #000000">.</span>
7. <span style="color: #000000">Obtain the admin token and domain from the third-party IdP you have selected in the authentication profile. Depending on the IdP, refer to the respective vendor documentation on how to obtain the admin token and domain.</span>
8. <span style="color: #000000">Synchronize user groups from the third-party IdP using the admin token and domain you retrieved from the IdP, or enable MS AD Sync if you have configured an LDAP profile. For more information, see </span>[*<span style="color: #000000">Synchronizing User Groups</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397703)<span style="color: #000000">.</span>
9. <span style="color: #000000">Create or modify security policies to include specific user groups to which you want to apply the security policies. For more information, see </span>[*<span style="color: #000000">Creating Security Policies</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469750)*<span style="color: #000000">.</span>*

<span style="color: #000000">For more information about access authentication, see the following:</span>

> Macro (children)