OnPrem MFA Setup

Will Weston 0 Reputation points
2024-07-19T18:17:22.71+00:00

I'm setting up a hybridID solution, I have the on-prem domain joined to the cloud domain, users are sync'd via Entra Connect, the test user has MFA enabled, and the user is in a group which is in the Staged Rollout Azure Multifactor Authentication. The test user is assigned a Entra P1 license. The test user has gone through the MFA verification process to the Authenticator APP. When logging into the cloud (portal.microsoft.com) MFA is checked/required.

My issue is when logging onto the on-prem machine, the user is not prompted for MFA. How do we force the on-prem PC to require MFA?

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,197 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 32,116 Reputation points Microsoft Employee
    2024-07-22T06:35:59.2866667+00:00

    @Will Weston Thank you for reaching out to us, As I understand you want to achieve a MFA prompt after entering the password for the users at the logon screen.

    In the past we used to have to have this option, currently on-premise MFA server is not available for new deployments - https://video2.skills-academy.com/en-us/entra/identity/authentication/how-to-migrate-mfa-server-to-azure-mfa

    If it's hybrid environment and you want Password + MFA when RDP to the clients, in that case you can leverage NPS extension with Azure MFA. Also, RDS infra with Azure MFA. https://video2.skills-academy.com/azure/active-directory/authentication/howto-mfa-nps-extension-rdg https://video2.skills-academy.com/azure/active-directory/authentication/howto-mfa-nps-extension

    For interactive logon if you are looking for MFA along with the password, then would recommend going with Windows Hello for Business approach, it replaces passwords with strong two-factor authentication on devices. This authentication consists of a type of user credential that is tied to a device and uses a biometric or PIN.

    Refer to this https://video2.skills-academy.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview for more information related to Windows hello for business/deployment models which you can choose based on your current infrastructure.

    Also, would recommend to read this Is Windows Hello for Business considered multi-factor authentication? The Windows Hello for Business key meets Azure AD multi-factor authentication (MFA) requirements and reduces the number of MFA prompts users will see when accessing resources.

    Let me know if you have any further questions, feel free to post back.

    Please remember to "Accept Answer" if answer helped, so that others in the community facing similar issues can easily find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.