Jump to content

Recommended Posts

Posted

Want to set up 2FA so users are required to use Microsoft Authenticator or similar as 2nd Factor when logging in from home via the Remote Gateway.

Anyone done this or something along these lines?

  • Thanks 1
Posted (edited)
Looks quite expensive based on user cost per month :(

 

It's the cheapest I could find as a middle-ground between cost and usability.

Edit: I'll clarify that we go for the "DUO MFA" solution at $3 pp/pm, works out at around £2.30. For all our staff it's about £170 per month. I don't consider that too bad if you weigh up the alternative!

 

Microsoft's 2fa solution is something like £4-something per person per month when I was investigating.

Edited by Mako
  • Thanks 1
Posted

I had this setup for us over the Summer - seems to work very well. We have a separate VM running NPS (RADIUS) that looks after the authentication and the Microsoft Authenticator App pipes up on their devices when they try to establish the connection. I got an external company to do the setup for us and it was money well spent.

 

We do have Conditional MFA setup with a P1 license in place to help facilitate this.

 

Pete

  • Thanks 1
Posted (edited)
When I set it up about a year ago somewhere, I used Rohos Logon Key and then either bought some hardware tokens or sent staff the QR code for individual logins to use with Google/Microsoft Authenticator. For the price, it was brilliant: https://www.rohos.com/support/rohos-logon-key-support/2-factor-authentication-for-remote-desktop-login-by-otp-sms/ - I provided staff with the RDP file to connect to the server through the gateway. Edited by Cache
  • Thanks 2
Posted
When I set it up about a year ago somewhere, I used Rohos Logon Key and then either bought some hardware tokens or sent staff the QR code for individual logins to use with Google/Microsoft Authenticator. For the price, it was brilliant: https://www.rohos.com/support/rohos-logon-key-support/2-factor-authentication-for-remote-desktop-login-by-otp-sms/ - I provided staff with the RDP file to connect to the server through the gateway.
Rohos seems to be a decent price for unlimited users at £332.
Posted
I was going to say, Application Proxy on Azure AD
I would say use the app proxy with the Web client.

The Azure NPS Plugin is more trouble as there is no on screen prompt.

 

I'm suprised that anyone has an RD Gateway on the Internet without MFA.

Posted

Just throwing this out there, with the current situation with schools and colleges being attacked

 

Is RDS the way to go can you not use an alternative solution for your staff?

Posted (edited)
Just throwing this out there, with the current situation with schools and colleges being attacked

 

Is RDS the way to go can you not use an alternative solution for your staff?

 

Protecting it with a RD Gateway protected with https and a MFA token effectively puts the Remote Desktop session inside a SSL VPN protected with a hardware token and that’s close enough to a gold standard.

 

If you can lock the MFA token to one you already use, hence why I suggest Azure Web Proxy if O365 is being used and is already protected by MFA, but I’ve also done this with Citrix and Okta, the users will find the experience relatively easy to use and it will be cost neutral as you already have the MFA infrastructure in place. I’d cheerfully recommend Citrix + Okta as a user friendly ‘alternative solution’ but it’s probably not within most educational establishments’ budgets right now.

Edited by Roberto
Posted
When I set it up about a year ago somewhere, I used Rohos Logon Key and then either bought some hardware tokens or sent staff the QR code for individual logins to use with Google/Microsoft Authenticator. For the price, it was brilliant: https://www.rohos.com/support/rohos-logon-key-support/2-factor-authentication-for-remote-desktop-login-by-otp-sms/ - I provided staff with the RDP file to connect to the server through the gateway.

 

Does Rohos work with the RDS HTML5 web client?

Posted

I don't know sorry and I'm no longer in post to test it.

 

I would expect that when you login it would just present the OTP code box for it to be entered within the HTML5 window, but I'm just guessing. There's a 15 day free trial. :)

  • Thanks 1
  • 3 weeks later...
Posted

Jumping in on this thread - any pros/cons as to whether to use the NPS MFA Extension vs Azure Application Proxy? Doesn't seem to be much in it - I've almost finished setting up a highly available RDS infrastructure with the NPS MFA extension but have just come across the Azure Application Proxy and wondering if that's a better fit...

My main concern with the NPS MFA Extension is the lack of visual cue for staff, but it does appear to work pretty well. Azure Application Proxy I couldn't find much documentation for setting up as highly available (2 RDWeb/Gateway servers) but as I only recently came across it I may have missed something...

 

Cheers,

Stephen

Posted

With the NPS extension, your RDGateway server is still fully exposed to the Internet like an unprotected one & you have ports directly open to your network - So you could have someone trying to log into it repeatedly via different IPs and you'd never know. They may still be able to gain login on your system, as from memory the 2fa only kicks in once you've tried to connect to a service (i.e after login)

 

The application proxy you don't have the ports open & you can apply conditional access policies. Also MS do a hella lot more blocking of dodgy traffic than you'll be able to keep up with.

 

For HA, you can use an RD broker to push people onto different RDS servers. I suppose if you need the front end bit HA'ing you could use normal Windows clustering.

  • Thanks 1
Posted

We've decided to remove Remote Desktop Entirely this summer.

 

With our MIS being cloud based and user files saved on onedrive, sharepoint for shared files there is no real need to keep it other than staff training.

Posted
We have decided to purchase the ROHOS 2FA system after using the trial version. The 2FA challenge only appears after the user logs in and tries to access one of the Remote Apps. As we only present RemoteApps via the HTML5 web client and no desktops this should be ok shouldn't it?
Posted

From the HA front i've currently got 2x RDS GW/WA, 2x RDS CBs, 2x RDS NPS, 4x RDS Session Hosts. I think from reading the docs I could put the AAP connector on both GW/WA servers without issues.

 

However, unless I'm missing something it looks like with AAP, the MFA prompt only kicks in/is applied when logging into the RDWeb page - once the RDP file has been downloaded and saved, they won't get prompted again. Does that sound right?

Previously I have never even publicised the RDWeb and just published the RDP file to make it more straight forward to staff/for macOS and iOS given instructions on how to setup using email address lookup. So I don't think the AAP route would give MFA from the macOS/iOS clients?

 

Is anyone able to clarify or point me in the direction of some clearer documentation?

Posted (edited)

You should just be able to use the link to the webclient. Presuming your using the app proxy with the webclient.

If using the RDP file method then the mfa only happens when the connection is made using the mstsc.exe not to the Rd Web. The webclient will make things more seamless. Users still need to enter their password so it's not complete SSO.

Edited by free780
Posted
Does that work on an iPad? I haven't tested the webclient thoroughly yet - staff are used to the full desktop client experience, so will need to ensure it is up to scratch. I gather the webclient doesn't support the additional UDP ports that make a huge difference to performance when connecting from Windows clients. I also have a small number of staff that remote to their personal desktops, via the RDS GW - which I don't think I can publish in the webclient?
  • 4 weeks later...
Posted
We have decided to purchase the ROHOS 2FA system after using the trial version. The 2FA challenge only appears after the user logs in and tries to access one of the Remote Apps. As we only present RemoteApps via the HTML5 web client and no desktops this should be ok shouldn't it?

 

I am just looking at ROHOS now - did you set it up with Google Authenticator and email out the codes? how did you find it?

 

Thanks

  • 1 month later...
Posted
Also trialing Rohos on our RDS setup. Worked OK for a single test user where I added the user manually and then scanned the QR code into the Google Authenticator app. Is that really the only way to do it or can Rohos email OTP/QR code out? Anyone tried the email options with an on-prem relay server or O365 account instead of GMail?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...