SafeNet Agent for ADFS
Product Description
Active Directory Federation Services (ADFS) supports a federated identity management solution extending distributed identification, authentication, and authorization services to web-based applications across organization and platform boundaries.
Multi-Factor Authentication (MFA) has traditionally meant using a smart card or other second factor with Active Directory–based authentication, such as Integrated Windows Authentication. This type of MFA can impose client-side requirements, such as smart card drivers, USB ports, or other client hardware or software that cannot always be expected with Bring Your Own Device (BYOD) client devices. ADFS introduces a pluggable MFA concept focused on integration with ADFS policy.
These release notes cover the SafeNet Agent for ADFS with SafeNet Trusted Access (STA). For SafeNet Authentication Service Private Cloud Edition (SAS PCE), see the SAS PCE release notes.
For additional information about features and system requirements, refer to SafeNet Agent for ADFS.
For a list of existing issues, refer to Known issues.
Release Information
Version 3.0.1 (08/2026)
SafeNet Agent for ADFS version 3.0.1 introduces the following feature and resolves the issue listed below:
- Number matching: Introduces MobilePASS+ push authentication with number matching for ADFS. Users must enter the number shown on the sign-in page into the push notification, helping prevent MFA fatigue and push-based attacks.
Resolved issue
| Issue | Synopsis |
|---|---|
| SASNOI-24553 | Summary: Following an agent upgrade, the sign-in page did not render correctly, preventing the multi-factor authentication prompt (passcode or push notification) from displaying and causing authentication to fail. |
Version 3.0.0 (02/2026)
SafeNet Agent for ADFS version 3.0.0 introduces the following features and resolves the issue listed below:
-
TLS 1.3: Adds support for the TLS 1.3 protocol to enhance transport security.
-
Extended operating system support: SafeNet Agent for ADFS is now compatible with Windows Server 2025.
Resolved issues
| Issue | Synopsis |
|---|---|
| SASNOI-18677 | Thales branding is now used throughout SafeNet Agent for ADFS. |
Version 2.43 (10/2023)
SafeNet Agent for ADFS version 2.43 introduces the following feature and resolves the issues listed below:
- Extended Operating System Support: SafeNet Agent for ADFS is now compatible with Windows Server 2022.
Resolved issues
| Issue | Synopsis |
|---|---|
| SASNOI-14351 | Summary: After upgrading to v2.41 or v2.42 date-wise logging was disabled. Now logs are generated with file location and date after the upgrade from v2.41 to v2.42 or v2.43. |
| SASNOI-14088 | Summary: Due to multiple IPs in the header, users were not able to authenticate. Authentication succeeds when the customer has configured the header to contain multiple IP addresses. |
Version 2.42
SafeNet Agent for ADFS version 2.42 introduces the following features:
-
FIPS support: The FIPS mode within the operating system with AES-GCM and RSA key standards as well as the FIPS mode for decrypting the agent's BSID key.
-
Enhanced Security: The AES-GCM encryption algorithm is now used to provide faster and a more secure way to protect data exchange between SafeNet Agent for ADFS and STA.
Version 2.41
SafeNet Agent for ADFS version 2.41 resolves the following issue:
Resolved issue
| Issue | Synopsis |
|---|---|
| SASNOI-10621 | Summary: SafeNet Agent for ADFS now successfully facilitates iPhone users' login to Office365 with the PUSH authentication while using multiple ADFS server and Farm configuration on the agent. |
Version 2.40
SafeNet Agent for ADFS version 2.40 introduces the following features and resolves the issue listed below:
-
ADFS 2019 (Windows Server 2019) Support: Support for ADFS 2019 (Windows Server 2019) is now added.
-
Use Alternate Login ID: On the SAS MFA Plug-in Manager window Policy tab, under Authentication Processing, the Use Alternate Login ID (e.g. Azure Login ID) check box is added.
Resolved issue
| Issue | Synopsis |
|---|---|
| SASNOI-9909 | Summary: Support for authentication if alternate ID is used in Azure AD. |
Version 2.30
SafeNet Agent for ADFS version 2.30 introduces the following feature and resolves the issue listed below:
- Support for Transport Layer Security v1.2: Support for Transport Layer Security (TLS) v1.2 protocol is now added.
Resolved issue
| Issue | Synopsis |
|---|---|
| SASNOI-9054 | Summary: Descriptive instructions included for Adding Relying Party Trust – Windows Server 2016 section. |
Known issues
This table provides a list of known issues as of the latest release.
| Issue | Synopsis |
|---|---|
| SASNOI-23755 | Summary: The agent stores its configuration in plain text on the server. The initialization file and the agent configuration file hold settings that are not encrypted on the server machine. Server machines are generally protected by the customer, but storing these values unencrypted leaves them readable to anyone who can reach the file system. A future release is expected to move this configuration out of the files that you edit directly. Instead, you will enter the values on the management console, which will store them encrypted. The agent will decrypt them at runtime for the communication it needs. This removes the need to keep sensitive values in plain text on the server. Workaround: Restrict access to the agent installation directory ( C:\Program Files\SafeNet\SAS\SafeNetMFA) to the accounts that require it, and manage the server according to your own hardening standards. |
| SASNOI-23498 | Summary: For GrIDsure tokens, PIN changes are not supported when the token template specifies the PIN type as Server-side Server Select. Workaround: There is no workaround for this PIN type. If your users need to change their GrIDsure PIN, assign a token template that specifies a different PIN type. |
| SAS-48759 | Summary: Due to some technical limitations, push OTP does not work for customers using Chrome or Edge browsers. Push OTP users in an ADFS environment do not receive push notification and are unable to complete their authentication journey. Customers using ADFS 4.0 on Windows Server 2016 are impacted. Workaround: - MFA is expected to work with push OTP service for Internet Explorer. - If Internet Explorer is not an option, we recommend the following to be executed from the ADFS server's command prompt, as a onetime activity: Set-AdfsResponseHeaders -SetHeaderName “Content-Security-Policy” -SetHeaderValue “default-src 'self' https://.sascloudservice.com https://.safenetid.com 'unsafe-inline' 'unsafe-eval'; script-src 'self' https://ajax.googleapis.com 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:;”" - Alternatively, you can upgrade to a later ADFS version. |
| SASNOI-6483 | Summary: SafeNet authentication might fail (with "An error occurred. Contact your administrator for more information" message) after installation or upgrade of an ADFS agent deployed in an ADFS Farm. In such a case, users will not be able to reach the SafeNet authentication page (after successful LDAP authentication) for all the requests serviced by secondary server(s). Workaround: After installation/upgrade, restart the ADFS service in the secondary servers. Each secondary server that sends authentication requests to STA must also be registered as an auth node, and Microsoft .NET Framework 4.8 must be installed manually on every secondary server. See ADFS federation server farm. |
| SASNOI-2102 | Summary: When you run Repair on the agent from Control Panel > Programs and Features, an error occurs and the repair does not complete. This will be fixed in a future release. Workaround: Do not use Repair. To restore a damaged installation, uninstall and reinstall the agent: 1. Back up the existing SAFENET-MFA.ini file from the agent installation directory (for example, C:\Program Files\SafeNet\SAS\SafeNetMFA\ini), so that you can restore your customized settings afterwards.2. Uninstall the agent, working in Run as administrator mode. 3. Reinstall the agent. See Install SafeNet Agent for ADFS. 4. Transfer your customized entries back into the new SAFENET-MFA.ini file, and confirm that IdpEnvironment is set to 1. See Set the agent variant for STA.If you reinstall the same version rather than installing a later one, you must remove the users and groups from the ADFS server after uninstalling. Failure to do so can result in authentication failures through the ADFS server. See Removing users and groups. |