itgeek Posted April 17, 2024 Posted April 17, 2024 Hi, I am looking to deploy Microsoft 2FA with our RemoteApps and RDS. We host this on prem and not in Azure. Has anyone deployed it this way and have any info they could share please? Thanks
pablo007 Posted April 17, 2024 Posted April 17, 2024 (edited) not Microsoft but we use cisco duo for this its brilliant and works really well at the right price point, a simple install on each rds server and the rest is done via an online portal, giving all the insight i need on logons. Edited April 17, 2024 by pablo007
mrbios Posted April 17, 2024 Posted April 17, 2024 Use this: https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-web-client-admin And chuck it behind Azure app proxy with pre-authentication set to Microsoft Entra ID. So long as your users require MFA on 365 off-prem, it'll force MFA for them before they can access it. Does mean you have to login with 365, complete MFA and then login again to the RDWeb app, but significantly better than not having MFA in front of it.
pete Posted April 17, 2024 Posted April 17, 2024 ^ I'd concurr with using the webclient behind Azure (now Entra) Application Proxy: https://learn.microsoft.com/en-us/entra/identity/app-proxy/application-proxy-integrate-with-remote-desktop-services If your devices are (or can be changed to) hybrid joined or native Azure look into the Global Secure Access (currently in Preview): https://entra.microsoft.com/#view/Microsoft_Azure_Network_Access/GetStarted.ReactView?Microsoft_AAD_IAM_legacyAADRedirect=true while you're at it.
dpswatson Posted April 24, 2024 Posted April 24, 2024 One thing I've found with MFA and RDS is that RDS does not allow for entering text or email codes into a dialogue box. Nor does it provide any feedback if MFA fails - it just doesn't connect. Staff have had to manually set Authenticator App - Notifications as their default in my account.microsoft.com so they get a yes/no prompt when they try to log in. It's the single biggest reason for "I can't get onto the RDS" queries.
NeoNebula Posted April 30, 2024 Posted April 30, 2024 I had experience deploying Microsoft 2FA with RemoteApps and RDS on on-premises infrastructure rather than in Azure. We used ADFS to set up 2FA authentication. This required us to configure the ADFS server and configure authentication rules to enable two-factor authentication. Additionally, we used MFA from Microsoft or other vendors to add an additional layer of protection. This process requires some preparation and setup, but overall it's pretty standard.
ITGuyNW Posted May 8, 2024 Posted May 8, 2024 This is what I'm trying to figure out now. We need remote access for SIMS on prem. I had a look at duo above but wouldn't that mean using a different app for 2FA? Also we are also A1, so until we are A3, some of these setup options might not be available to us.
pablo007 Posted May 8, 2024 Posted May 8, 2024 This is what I'm trying to figure out now. We need remote access for SIMS on prem. I had a look at duo above but wouldn't that mean using a different app for 2FA? . Yes but most folk have more than one MFA app and if I could avoid anything Microsoft I would, its always so much much more hassle than anything other vendors do.
pablo007 Posted May 10, 2024 Posted May 10, 2024 Do they? Most folk have more than one MFA app? yeah you're probably right on this, most of us (techies etc.) do so as not to have all eggs in one basket so to speak but but i guess other users do not. that said duo has its own and I think cpoms does and I haven't any really push back.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now