How to service a domain after hours secured by MFA

JpSmith 0 Reputation points
2024-07-15T21:12:18.6766667+00:00

We are trying to integrate MFA into our Hybrid Azure Domain. Our main issue is that support works late into the night, and it would not be convenient to call a user asking for their one time code. What is the best way to facilitate MFA giving Admins access to mfa protected machines and apps? We also currently use SSO thru Azure and secure the domain with conditional access. Thanks

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,696 questions
Microsoft Entra
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,460 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Fabio Andrade 725 Reputation points Microsoft Employee
    2024-07-15T23:42:21+00:00

    Hi @JpSmith

    Thanks for reaching out to Microsoft Q&A

    I'm not sure if I understood your scenario, could you please provide more details?

    • How do your users login and MFA to the "protected machines", do they use user/password and then have to enter a one-time code from Authenticator app or other like RSA?
    • Are those machines Azure VMs or on-premises servers?

    Technically, each user should have their own credentials and MFA methods, so it would be great to have more information about how your environment works.

    Thanks,

    Fabio

    0 comments No comments