Jump to content

Recommended Posts

Posted

Hi,

 

I am looking to deploy Microsoft 2FA with our RemoteApps and RDS. We host this on prem and not in Azure. Has anyone deployed it this way and have any info they could share please?

 

Thanks

Posted (edited)
not Microsoft but we use cisco duo for this its brilliant and works really well at the right price point, a simple install on each rds server and the rest is done via an online portal, giving all the insight i need on logons. Edited by pablo007
Posted

Use this:

https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-web-client-admin

 

And chuck it behind Azure app proxy with pre-authentication set to Microsoft Entra ID. So long as your users require MFA on 365 off-prem, it'll force MFA for them before they can access it. Does mean you have to login with 365, complete MFA and then login again to the RDWeb app, but significantly better than not having MFA in front of it.

Posted

^ I'd concurr with using the webclient behind Azure (now Entra) Application Proxy:

 

https://learn.microsoft.com/en-us/entra/identity/app-proxy/application-proxy-integrate-with-remote-desktop-services

 

If your devices are (or can be changed to) hybrid joined or native Azure look into the Global Secure Access (currently in Preview): https://entra.microsoft.com/#view/Microsoft_Azure_Network_Access/GetStarted.ReactView?Microsoft_AAD_IAM_legacyAADRedirect=true while you're at it.

Posted

One thing I've found with MFA and RDS is that RDS does not allow for entering text or email codes into a dialogue box. Nor does it provide any feedback if MFA fails - it just doesn't connect.

Staff have had to manually set Authenticator App - Notifications as their default in my account.microsoft.com so they get a yes/no prompt when they try to log in.

It's the single biggest reason for "I can't get onto the RDS" queries.

Posted
I had experience deploying Microsoft 2FA with RemoteApps and RDS on on-premises infrastructure rather than in Azure. We used ADFS to set up 2FA authentication. This required us to configure the ADFS server and configure authentication rules to enable two-factor authentication. Additionally, we used MFA from Microsoft or other vendors to add an additional layer of protection. This process requires some preparation and setup, but overall it's pretty standard.
  • 2 weeks later...
Posted

This is what I'm trying to figure out now. We need remote access for SIMS on prem. I had a look at duo above but wouldn't that mean using a different app for 2FA?

 

Also we are also A1, so until we are A3, some of these setup options might not be available to us.

Posted
This is what I'm trying to figure out now. We need remote access for SIMS on prem. I had a look at duo above but wouldn't that mean using a different app for 2FA?

.

 

Yes but most folk have more than one MFA app and if I could avoid anything Microsoft I would, its always so much much more hassle than anything other vendors do.

Posted
Do they? Most folk have more than one MFA app?

 

 

yeah you're probably right on this, most of us (techies etc.) do so as not to have all eggs in one basket so to speak but but i guess other users do not. that said duo has its own and I think cpoms does and I haven't any really push back.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...