Jump to content

Recommended Posts

Posted

Hi Everyone,

 

I am currently looking at utilizing the MFA capabilities within our Office 365 accounts for our Remote Access (RDS). I have seen this can be done but it requires Azure AD Premium. Has anyone done this with any success and if so how many licenses did you need to buy? all of our users can access the RDS Farm from home but only staff and admins use MFA on their accounts. It seems quite expensive from what I've seen!

Posted
We went down the route of getting the A3 Enterprise Mobility and Security addon for our existing OVS-EES agreement (around £7-£8 per FTE) which we assigned to our staff so we get Conditional Access MFA, inTune, and also access to the MS ApplicationProxy. It is this we are using to provide access for our staff to our RDS setup, so users have to authenticate with Office 365 in the first instance (so MFA is processed if required) and then authorised users get the Application visible along with the rest of the Office 365 Apps (such as Word etc)
Posted
We went down the route of getting the A3 Enterprise Mobility and Security addon for our existing OVS-EES agreement (around £7-£8 per FTE) which we assigned to our staff so we get Conditional Access MFA, inTune, and also access to the MS ApplicationProxy. It is this we are using to provide access for our staff to our RDS setup, so users have to authenticate with Office 365 in the first instance (so MFA is processed if required) and then authorised users get the Application visible along with the rest of the Office 365 Apps (such as Word etc)

 

I see so because we have an OVS agreement too any additional products like that are based on the FTE still? I wouldn't have to buy 1500 licenses for example?

  • 2 years later...
Posted (edited)

For users without a P1/P2 there is the option of using programmable hardware tokens.

 

The general idea with programmable tokens is that the token acts as a direct replacement for the authentication app on a mobile phone. This does mean that they can be used wherever OTP generating authentication apps can be used, and there is the benefit that time drift can be corrected (by reprogramming the tokens). You also have the advantage that the tokens can still be used as standard pre-programmed tokens. On the downside the users could program the tokens themselves using an NFC enabled mobile phone (this can be a downside as they may chose to claim the tokens as lost and use them elsewhere).

 

There are also some Fido2 keys that can be programmed to produce time based OTP codes (for this feature you need Fido keys that can produce TOTP codes as Microsoft will not accept HOTP codes), however in this example OTP is only a second best solution as FIDO does offer phishing protection. Also, with Fido tokens you have to ensure the USB port is compatible with what it will be connected with (in some cases company policies are an issue here).

Edited by Brixy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...