Microsoft MFA (onprem or Azure)

Peter Schober peter.schober at univie.ac.at
Sat Mar 13 12:08:42 UTC 2021


* Goggins, Patrick via users <users at shibboleth.net> [2021-03-12 20:58]:
> The IdP Proxy might work but there are limitations there. Otherwise
> there’s the NPS role
> (https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension),
> but those requests are via Radius which is another issue.

What's the protocol used between the "NPS Server" and "Azure MFA"?
And how does the subject (using a "VPN client") complete the
"secondary authentication" triggered by the "NPS Extension"? Seemingly
outside of the VPN client and RADIUS protocol -- by starting a local
web browser on the client's machine pointed to some MS web server?

Well, if you own all the parts (client OS, client software, server OS
in the client's data center, external services/APIs) I guess anything
is possible...

-peter


More information about the users mailing list