Azure MFA with RDS using NPS Extension does not bypass trusted location/IP's

adamweldon 1 Reputation point
2020-10-05T10:03:25.137+00:00

Hello,

We have several RDS farms setup and they are using Azure MFA with the NPS Extension.

However, we have never been able to get trusted locations/IP's to work.

  1. We have put the local IP's of the on-prem environment into the whitelist on the NPS side (Reg key), still no success
  2. We have put the external locations IP addresses into the Trusted Locations - still no success.

No matter how we've configured it, it seems that using RDS with Azure MFA through the NPS extension, you cannot use any trusted locations to bypass the MFA requirement Users always get prompted to pass MFA, inside the trusted locations (i.e. their office).

We consulted with MS Support a bout a year ago on the issue and it was classified as a known issue.

Has this progressed, is this still a known problem?

Thank you

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marilee Turscak-MSFT 37,206 Reputation points Microsoft Employee Moderator
    2020-10-05T23:05:35.387+00:00

    Hi @adamweldon ,

    Yes, this is still a known issue. There is an open feature request for it here which you can vote on and comment on. I'll also add a request internally to bubble this up to the product team.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.