question

HenryNiekoop-2622 avatar image
0 Votes"
HenryNiekoop-2622 asked HenryNiekoop-2622 answered

Windows 2019 TS server with mfa authentication

I have 2 questions:

  • Can you configure mfa authentication with a single rdp session host (without an rd gateway)?


  • Also can you configure mfa authentication for the first sign in on the RD gateway? Normally you will have to sign in 2 times. First for the website portal and second when you sign in with the rdp client. By default mfa prompts the user only when the user connects with the rdp client. However we would like to have users authenticate 1 time only with MFA.

Thanks.

remote-desktop-servicesazure-ad-multi-factor-authentication
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JiaYou-MSFT avatar image
0 Votes"
JiaYou-MSFT answered JiaYou-MSFT edited

HI HenryNiekoop-2622,

  1. think the answer is negative. MFA need NPS server and NPS extension, meanwhile NPS server as authentication bridge between Azure AD and local Active Directory and there is "central servre running NPS" option on RDgateway server, So we think about "if there is no RDgateway server and there will be only sepearate NPS server in RDS environment, how win10 client contact session host server through this NPS server to complish MFA?"

2."However we would like to have users authenticate 1 time only with MFA."
I am think about RDWeb SSO, we check if it can work with MFA in your RDS environment.May be we can not implement to have users authenticate 1 time only with MFA.

"ince password guessing and login access are among the top causes of cyber attacks, additional layers of protection are essential. Multi-factor authentication (MFA) requires users to enter two or more identification factors to access an application."

Single Sign-On vs. MFA: Do You Know The Difference?
https://fortifiedhealthsecurity.com/blog/single-sign-on-vs-mfa-do-you-know-the-difference/

Please Note: Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice.

============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HenryNiekoop-2622 avatar image
0 Votes"
HenryNiekoop-2622 answered

Thanks, good to know about Single Sign On for Remote Desktop Infrastructure. I realized that after signing into the RDWeb landing page users can download the rdp client file and save it on their local machine. From that point on you do not have to sign in on the landing page anymore but start a session directly with the rdp file.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HenryNiekoop-2622 avatar image
0 Votes"
HenryNiekoop-2622 answered JiaYou-MSFT rolled back

Thanks, good to know about Single Sign On for Remote Desktop Infrastructure. I realize that after signing into the RDWeb landing page users can download the rdp client file and save it on their local machine. From that point on you do not have to sign in on the landing page anymore but start a session directly with the rdp file.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HI HenryNiekoop-2622,

IIs there other thing I can help you?

0 Votes 0 ·
HenryNiekoop-2622 avatar image
0 Votes"
HenryNiekoop-2622 answered

I'm good. thanks.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.