RRAS VPN with Microsoft Entra MFA reauthentication time limit

Krystian Blaszkowicz 20 Reputation points
2025-03-18T15:30:56.01+00:00

Hello,

We have an on-premise RRAS hosting an SSTP VPN, we have also set this up with RADIUS to a NPS server with Entra MFA configured. This solution works fine on a good internet connection, users are prompted and stay connected, but not all users have reliable connections, especially those travelling or working far abroad, this means every time the connection drops, they have to authenticate all over again, for something this has been as frequent as every couple minutes. Is there a way to have MFA not be asked every time upon connecting? I have looked through Entra conditional access it seems there is no clear answer in either the portal or documentation.

The 90 day MFA reauthentication for things like browser logins works fine, and we have no issue with that, the issue is specific to the MFA authentication over the NPS server having no reauthentication time.

Microsoft Security | Microsoft Authenticator
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.