RD-Gateway with NPS Server and NPS Extension, Windows Firewall issue. Azure MFA

Tim 66 Reputation points
2023-01-30T08:41:14.2633333+00:00

Hi!

We recently configured a new NPS Server with the NPS extension for our Remote Desktop Gateway to do a MFA against the AzureAD.

The odd thing is, we can only get it to work when we disable the Windows Firewall on the NPS server.

All ports necessary for NPS; UDP ports 1812, 1813, 1645 are open but when the Windows Firewall on the NPS is enabled we cannot do a MFA to Azure.

Is there a port or application that we are missing?

Best regards,

Tim

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pradeep Kini 75 Reputation points
    2023-01-30T11:59:46.8533333+00:00

    is the MFA failing with Windows Firewall but works with firewall disabled. for the NPS extensions to support secondary MFA it needs to communicate with the following MS URLs on 443

    if that is not the case then i would recommend you to enable Wireshark or similar and look at the traffic being blocked. or if you have firewall logging enabled you could look at what traffic is filtered

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.