W10 PRO - M.F.A for O365 ACCOUNT (AZURE ACTIVE DIRECTORY PREMIUM p1/p2) as Cisco Duo does

Renato Pereira 181 Reputation points
2021-08-05T23:18:30.597+00:00

Hi,

We have a customer concerned with the computer used by the FINANCIAL employee. Does anyone if MS has a tool for enable M.F.A during eache Windows logon, as Cisco DUO does in this vídeo below?
https://youtu.be/eQK3VxeKxWA?t=390


usefull links:


https://allthingscloud.blog/oath-totp-hardware-tokens-with-azure-multi-factor-authentication

https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-mfa-howitworks

The following additional forms of verification can be used with Azure AD Multi-Factor Authentication:

  • Microsoft Authenticator app
  • OATH Hardware token
  • SMS
  • Voice call

https://www.microsoft.com/en-us/security/business/identity-access-management/mfa-multi-factor-authentication

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,597 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Renato Pereira 181 Reputation points
    2021-08-07T19:05:00.49+00:00

    I found another option from ESET

    https://www.eset.com/us/business/solutions/identity-and-data-protection/?utm_source=expert-insights&utm_medium=affiliate&utm_campaign=2fa&sfdccampaignid=7011n000000JpuRAAS%20#secure-authentication

    Protection support
    Virtual Private Networks (VPN), Remote Desktop Protocol (RDP), Outlook Web Access (OWA), VMware Horizon View and RADIUS-based services are all natively supported by ESET Secure Authentication.

    0 comments No comments

  2. Renato Pereira 181 Reputation points
    2021-08-14T21:13:17.963+00:00

    Accordingly to ESET distributor, the product 'ESET Secure Authentication' can handle Windows login; but here in a LAB environment, seems that it requires an 'authentication server' running Database also - since we have more and more customers going to the cloud and replacing local servers, we will try 'Cisco Duo'.

    ---------------------------------------------------

    123322-eset-secure-authentication.png

    0 comments No comments

  3. Marilee Turscak-MSFT 34,051 Reputation points Microsoft Employee
    2021-09-29T23:55:55.733+00:00

    Windows Hello For Business sounds like the best solution for you. It essentially enforces 2FA every time a user logs into a device. https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview

    0 comments No comments