Azure MFA with Exchange Server On-Premises

Jamil Saif 21 Reputation points
2021-04-11T19:14:17.307+00:00

Greetings All,

I have Exchange On-Premises, and I am planning to introduce ActiveSync to allow mobile users access to their mailboxes (emails, calendar, etc..).
To Secure ActiveSync, it is recommended by Microsoft to enable MFA, where I have Azure E3 Subscription that includes MFA. my question is, does this subscription's MFA support my setup? or I need other solutions?

Thanking you

Jamils

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,373 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Joyce Shen - MSFT 16,646 Reputation points
    2021-04-12T03:42:40.363+00:00

    Hi @Jamil Saif

    Please refer to the discussion in below thread about MFA for on-premise Exchange activesync

    Exchange Server 2016 On-Premise and 2FA/MFA

    Exchange ActiveSync with Azure AD Application Proxy

    For more information about Tutorial: Secure user sign-in events with Azure AD Multi-Factor Authentication

    I also see a workaround using Activesync Device Quarantine. All new ActiveSync devices go into a quarantined state until approved by IT. The IT department has to get confirmation from the user that they added the device, and if they had an old device, what was done with it to properly wipe the email off.


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
     


  2. Jamil Saif 21 Reputation points
    2021-04-12T07:34:00.847+00:00

    Hi @Joyce Shen - MSFT

    Thank you very much for your reply.
    But, there is some confusion, at least for me, when I got theses two Microsoft articles about the subject:

    https://learn.microsoft.com/en-us/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication?view=o365-worldwide

    https://learn.microsoft.com/en-us/Exchange/clients/outlook-for-ios-and-android/use-hybrid-modern-auth?view=exchserver-2019

    any clarifications on that?

    Thanking you

    Jamils