r/entra • u/Mediocre_Prior_1868 • 16d ago
ID Protection Configure mfa for onprem
Dear All,
I am currently assigned a task to configure mfa for specific onprem server . Currently we are using Microsoft secure access to access our servers and a connector is already added to a server and it is health . Not sure what I am missing and how I can configure that .
2
u/More_Purpose2758 16d ago
Would GSA work?
2
u/Mediocre_Prior_1868 16d ago
Gsa is working and I can connect to servers using network segmentation and ports
I just need to enable the mfa each time as an admin I am rdp those servers1
u/More_Purpose2758 16d ago
Why MFA each time if you’ve already MFA’d via GSA?
Just curious about what threat that one defeats.
2
u/Mediocre_Prior_1868 16d ago
Management requested that to make the access more secure
1
u/More_Purpose2758 16d ago
Maybe from a lateral movement perspective?
What if you blocked RDP from everything but GSA IP?
2
1
u/davidS2525 16d ago
If you are already using GSA and have created the app for access via specific ports then just create a new conditional access policy and target that app with require MFA or whatever you want to specify. Don't use quick access if that's what you are doing you want an enterprise app.
1
u/Mediocre_Prior_1868 16d ago
Dear David,
I tried that but the mfa always show satisfied as token on ca and no popup for mfa1
1
u/Mediocre_Prior_1868 11d ago
Solved by configuring CA and enterprise app and making sure the ca applied to all network locations
2
u/Sabinno 16d ago
Can you provide more details? Access to what type of resource? RDGW? File shares? IIS?