Exchange Server 2016 On-Premise and 2FA/MFA

Dhillan Kalyan 56 Reputation points
2020-10-31T15:49:18.753+00:00

Hi

I am trying to find some specific info with regards to Exchange Server 2016 on-premise implementation and 2FA/MFA and not finding much luck.

I have a client who is looking to implement a 2FA solution for their on-premise exchange environment. They currently have PingFederate in the environment and are implementing Symantec 2FA as the MFA provider.

From my understanding I believe that we can implement 2FA without any problems for OWA but I have also been asked to investigate the implementation of 2FA for EWS, ActiveSync and the Outlook Mobile app. This is where I cannot find information.

Is it possible to implement 2FA for these services? Please advise

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,363 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Ashok M 6,506 Reputation points
    2020-11-01T07:28:26.417+00:00

    Hi,

    To my knowledge, supported services for MFA in Exchange on-premise are OWA/ECP. There are various methods to achieve this,

    1. Using ADFS
    2. Cloud based - Azure
    3. Reverse proxy + cloud based - for instance, reverse proxy can be integrated with NPS for RADIUS and using NPS extension on that server for secondary authentication in Azure
    4. Third party products like PingFederate/Duo and that has the clear documentation on the product itself for configuring MFA for Exchange on-premise

    http://msexchangeguru.com/2017/01/16/secure-owa-ecp-with-mfa/
    https://practical365.com/exchange-server/exchange-web-services-bypass-multi-factor-authentication/
    https://social.msdn.microsoft.com/Forums/en-US/d28e3947-0a19-44d9-b39f-db9a4f6c21f3/mfa-on-premises-exchange-2016?forum=windowsazureactiveauthentication

    If the above suggestion is helpful, please click on "Accept Answer" and Upvote it.

    1 person found this answer helpful.

  2. Lucas Liu-MSFT 6,161 Reputation points
    2020-11-02T07:28:31.117+00:00

    Hi @Dhillan Kalyan ,
    I agree with what AshokM-8240 said.
    In addition, if you use a third-party product to set up MFA for ActiveSync and Outlook on mobile, please note that there are requirements for your mobile system. For specific restrictions, please refer to the instructions of each product.

    ----------

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. David McBride 301 Reputation points
    2021-07-29T16:50:49.637+00:00

    @Ashok M
    My specific goal is to implement 2FA for On-Prem Exchange 2019 multi-tenant. Above you said the goal could be accomplished by various methods. I'm specifically interested in 1. Using ADFS and 2. Cloud based - Azure. I can find articles that talk about these topics but not specifically how to accomplish my goal. Can you give more info on options 1 and 2 please?
    Thanks!!


  4. Keith Clark 1 Reputation point
    2021-11-11T13:41:30.7+00:00

    I also am being tasked with 2FA for OWA onprem Exchange 2016 server. I already have 2FA established throughout the domain and remote users with hardware Yubikey Smart cards. I was hoping I could use these same cards rather than having to now support an additional 2FA solution. Is it possible within exchange 2016 On Prem or 2019 Server to support Hardware Tokens FIDO2 ??? Is there any kind of support for my yubikeys to do 2fa for OWA or am I stuck with having to purchase additional solution?


  5. SH-1616 61 Reputation points
    2022-03-08T11:25:31.46+00:00

    Hi,

    I had the same challenge and ended using DUO 2FA for Exchange 2016 OWA on premise, the setup and configuration was straightforward
    owa