Antivirus, Endpoint Detection and Response (EDR), and other endpoint security software can apply network controls independently of your standard firewall configuration. As a result, Rublon MFA for Windows may be unable to connect to the Rublon API even when outbound TCP port 443 is open on your firewall.
Network communication used by the Rublon MFA for Windows connector can be performed in the Windows SYSTEM context. Some endpoint security products can apply different network policies depending on the process, application, or security context. Therefore, a successful connection to the Rublon API from a browser, PowerShell, or another application running as the logged-in user does not necessarily confirm that the connector itself can connect.
What should I check?
If Rublon MFA for Windows cannot communicate with the Rublon API, check the following:
1. Confirm the firewall configuration. Make sure outbound TCP port 443 is allowed for the Rublon API address configured in the connector. By default, the connector uses https://core.rublon.net/. For more information, refer to How should I configure my firewall for Rublon MFA?.
2. Check your antivirus or EDR logs and policies. Look for blocked or terminated outbound connections associated with Rublon MFA for Windows. Pay particular attention to network protection, application control, host firewall, web filtering, and other network filtering features.
3. Check network policies that apply to the SYSTEM context. Firewall, antivirus, EDR, or other endpoint security policies may restrict network access differently depending on the process or security context. Do not rely only on connectivity tests performed as the currently logged-in administrator. Verify that outbound HTTPS traffic to the configured Rublon API address over TCP port 443 is allowed when the Rublon MFA for Windows connector operates in the Windows SYSTEM context.
4. Create an appropriate allow rule or exception if required. The exact procedure depends on your antivirus or EDR product. Configure the product to allow Rublon MFA for Windows to communicate with the configured Rublon API address over TCP port 443. If your security product uses IP-based rules, refer to What are Rublon MFA's IP ranges?.
5. Test an actual authentication. After changing the endpoint security configuration, perform a Windows or RDP sign-in protected by Rublon MFA and verify that the authentication completes successfully. Also check your antivirus or EDR logs to make sure the connection is no longer being blocked.
If your endpoint security solution performs HTTPS/TLS inspection, web filtering, or other traffic inspection, check whether these features are interfering with the connection to the Rublon API and configure an appropriate exception according to the product vendor's documentation.
Important
Do not disable antivirus, EDR, firewall, or network protection globally to make Rublon MFA work. Create the narrowest exception supported by your security product, limited to the required Rublon communication.
Because antivirus and EDR products use different network filtering mechanisms and policy formats, we cannot provide a single configuration procedure that applies to every product.
Helpful Links
How should I configure my firewall for Rublon MFA?
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article