Cloud Azure MFA to secure on-prem Exchnage Server OWA without ADFS

redamaleki 1 Reputation point
2020-04-07T20:07:14.913+00:00

Microsoft no longer supports MFA server for new deployments, but recommends using the [NPS Extension for MFA configuration](https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg "MFA NPS Extension").

[Hybrid Modern Authentication](https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-hybrid-modern-authentication-for-exchange-on-premises/ba-p/607476 "Hybrid Modern Authentication") works for Outlook clients, but does not appear to provide MFA enforcement for OWA. In our scenario, we have Azure AD Connect deployed with pass-through authentication (No ADFS). Is there a way to enforce MFA on OWA for end users either using the NPS extension or another AD cloud service? We have Exchange 2016 Server with CU 15 deployed.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,342 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. jLight 201 Reputation points
    2020-04-07T20:33:24.587+00:00

    You might try setting up a Conditional Access requiring MFA and then selecting Office 365 application (cloud apps, not the software).

    7251-chrome-ahyrvspbjs.png