microsoft nps mfa extension

Alexander Bussohn 1 Reputation point
2022-10-17T14:28:21.997+00:00

Hello together,

we want to use microsoft nps server with azure mfa extension in future.
I got this working so far, but i have one question related to radius access-challenge messages.
If i authenticate via azure mfa extension and entered the first factor (username and password) i didn't receive any information what to do. For example a text mesage like this
"Please confirm multi factor authentication". Please notice: I receive the multi factor prompt, but i wish to inform the user, that the system is waiting for the second factor of authentification.
Is there any opportunity to send a Radius Access-Challenge Message with Attribute Type 18 (Reply-message)?
Is this anywhere working like explained?

Thanks for information

Regards
Alexander

Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. JimmySalian-2011 42,511 Reputation points
    2022-10-17T14:52:11.073+00:00

    Hi Alexander,

    Just check this page and it has some steps KB44686 also follow this article and should help you in configuration of policies for Radius - howto-mfa-nps-extension
    Hope this helps.


    Please don't forget to upvote and Accept as answer if the reply is helpful

    If this answer helped you please mark it as "Verified" so other users can reference it.


  2. Akshay-MSFT 17,961 Reputation points Microsoft Employee Moderator
    2022-10-20T12:24:55.633+00:00

    Hello @Alexander Bussohn ,

    I would recommend checking what does NPS extension server log shows under path:

    Applications and Services Logs > Microsoft > AzureMfa > AuthN > AuthZ

    and based upon the error's please validate the following:

    Thanks
    Akshay Kaushik

    Please "Accept the answer" and "Upvote" if the suggestion works as per your business need. This will help us and others in the community as well.


  3. Nick Doud 6 Reputation points
    2023-10-03T20:27:08.9233333+00:00

    I believe I have done all this and still don't get the MFA prompt???

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.