MFA for onprem domain controllers

Janus Bariñan 1,126 Reputation points
2021-02-10T07:13:28.477+00:00

Is it possible to have MFA integrated to onpremise AD?
Like when they login using the domain admin account they will go through MFA.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
0 comments No comments
{count} vote

Accepted answer
  1. Johan Heyneke 81 Reputation points Microsoft Employee
    2021-02-10T07:36:02.82+00:00
    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Daniele Bona 6 Reputation points
    2021-10-02T08:08:33.063+00:00

    Guys,

    I think today a solution is technically possible using FIDO2 keys and the old domain "SCRIL" feature.
    Also Remote Credential Guard and Protected Users are components required.

    Here all the details :

    https://techcommunity.microsoft.com/t5/security-compliance-and-identity/removing-onprem-domain-admins-passwords-with-azure-passwordless/m-p/2803878

    Please test yourself reporting feedbacks :) (I only tested in my lab , never in production so a running test might be appreciated ..)

    1 person found this answer helpful.
    0 comments No comments

  2. Fan Fan 15,291 Reputation points Microsoft Vendor
    2021-02-10T08:39:02.127+00:00

    Hi,
    As of July 1, 2019, Microsoft no longer offers MFA Server for new deployments.
    New customers that want to require multi-factor authentication (MFA) during sign-in events should use cloud-based Azure AD Multi-Factor Authentication.
    For more information , you can refer to the following link:
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa

    Best Regards,


  3. Janus Bariñan 1,126 Reputation points
    2021-02-13T14:59:16.627+00:00

    Thanks for your answers guys. I'm sorry If I can mark only one as Answer.

    By the way, to help others who are also needing this, we are going to test Okta's service to apply MFA for on-prem DCs.


  4. Chris Bunn 0 Reputation points
    2023-01-25T16:33:17.7333333+00:00

    Hi. You can enable granular MFA on any/all on-premise AD users with a third party solution UserLock.

    More information here: [https://www.isdecisions.com/products/userlock/multi-factor-authentication-mfa-active-directory.htm

    0 comments No comments