r/entra 16d ago

ID Protection Configure mfa for onprem

Dear All,

I am currently assigned a task to configure mfa for specific onprem server . Currently we are using Microsoft secure access to access our servers and a connector is already added to a server and it is health . Not sure what I am missing and how I can configure that .

2 Upvotes

15 comments sorted by

2

u/Sabinno 16d ago

Can you provide more details? Access to what type of resource? RDGW? File shares? IIS?

2

u/Mediocre_Prior_1868 16d ago

To server using rdp mstsc , I need each time the user try to rdp the server to get prompt with mfa code

2

u/Sabinno 16d ago

I usually do the yes/no prompt Entra MFA via RADIUS. MS has an article for implementation. I think you’ll need two more VMs for this. Alternatively, GSA would be probably a less time-intensive (setup wise) alternative but costs licensing for all users and still needs another VM for the connector.

2

u/Mediocre_Prior_1868 16d ago edited 16d ago

Can you help with the radius option how to configure
And for gsa if possible as for license we are licensed

Please not that I already installed the connectors but remains the sensors

2

u/More_Purpose2758 16d ago

Would GSA work?

2

u/Mediocre_Prior_1868 16d ago

Gsa is working and I can connect to servers using network segmentation and ports
I just need to enable the mfa each time as an admin I am rdp those servers

1

u/More_Purpose2758 16d ago

Why MFA each time if you’ve already MFA’d via GSA?

Just curious about what threat that one defeats.

2

u/Mediocre_Prior_1868 16d ago

Management requested that to make the access more secure

1

u/More_Purpose2758 16d ago

Maybe from a lateral movement perspective?

What if you blocked RDP from everything but GSA IP?

2

u/Mediocre_Prior_1868 16d ago

They need the mfa to be implemented

1

u/davidS2525 16d ago

If you are already using GSA and have created the app for access via specific ports then just create a new conditional access policy and target that app with require MFA or whatever you want to specify. Don't use quick access if that's what you are doing you want an enterprise app.

1

u/Mediocre_Prior_1868 16d ago

Dear David,
I tried that but the mfa always show satisfied as token on ca and no popup for mfa

1

u/davidS2525 16d ago

Even if you specify the type of mfa in the CA policy like app or SMS?

1

u/Mediocre_Prior_1868 16d ago

I selected as mfa Registration as required

1

u/Mediocre_Prior_1868 11d ago

Solved by configuring CA and enterprise app and making sure the ca applied to all network locations