question

MSheerazAnsari-2409 avatar image
0 Votes"
MSheerazAnsari-2409 asked MSheerazAnsari-2409 commented

ADFS and On-Premises MFA server upgrade

Hello Tech Community,

We have a customer currently using 2012 R2 ADFS with On-Premises MFA version 8.0.1. Current setup includes three ADFS servers hosting On-Premises MFA role on a single farm and three ADFS WAP servers (2 Primary and 1 DR). Customer wants to upgrade this infrastructure to 2016 Based ADFS along with same On-Premises MFA version 8.0.1. I would like to know following.

  • Has anyone tested MFA version 8.0.1 on Windows Server 2016?

  • What should be the approach of this infrastructure upgrade as there are critical applications dependent on MFA authentication?

  • Or should we deploy MFA latest version (8.0.5) with ADFS 2016?

  • Please also mention fall back approach during this upgrade.

Thanks in advance.




adfsazure-ad-multi-factor-authentication
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

alfredorevilla-msft avatar image
0 Votes"
alfredorevilla-msft answered MSheerazAnsari-2409 commented

Hello,

  1. MFA server 8.0.1 works with Windows Server 2016.

  2. The safest approach would be to add new MFA Servers to the existing collection and turn off older MFA servers.

  3. That would be the best in tandem with previous recommendation.

  4. Please follow steps detailed in Back up and restore Azure MFA Server.


Please let me know if you need more help. If the answer was helpful to you, please accept it and, optionally, provide feedback so that other members in the community can benefit from it.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks Alfredorevilla,

We have tested MFA server 8.0.1 on Windows Server 2016 in a lab and it perfectly worked. We have also deployed it in production and it has worked well. Real challenge we had for diverting traffic from load balancer to the new server - rest of the things for ADFS upgrade part worked pretty well. Thanks.

0 Votes 0 ·