MFA for onprem domain controllers

Janus Bariñan 1,126 Reputation points
2021-02-10T07:13:28.477+00:00

Is it possible to have MFA integrated to onpremise AD?
Like when they login using the domain admin account they will go through MFA.

Windows for business Windows Client for IT Pros Directory services Active Directory
0 comments No comments
{count} vote

Accepted answer
  1. Johan Heyneke 81 Reputation points Microsoft Employee
    2021-02-10T07:36:02.82+00:00
    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Daniele Bona 6 Reputation points
    2021-10-02T08:08:33.063+00:00

    Guys,

    I think today a solution is technically possible using FIDO2 keys and the old domain "SCRIL" feature.
    Also Remote Credential Guard and Protected Users are components required.

    Here all the details :

    https://techcommunity.microsoft.com/t5/security-compliance-and-identity/removing-onprem-domain-admins-passwords-with-azure-passwordless/m-p/2803878

    Please test yourself reporting feedbacks :) (I only tested in my lab , never in production so a running test might be appreciated ..)

    1 person found this answer helpful.
    0 comments No comments

  2. Anonymous
    2021-02-10T08:39:02.127+00:00

    Hi,
    As of July 1, 2019, Microsoft no longer offers MFA Server for new deployments.
    New customers that want to require multi-factor authentication (MFA) during sign-in events should use cloud-based Azure AD Multi-Factor Authentication.
    For more information , you can refer to the following link:
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg
    https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfa

    Best Regards,


  3. Janus Bariñan 1,126 Reputation points
    2021-02-13T14:59:16.627+00:00

    Thanks for your answers guys. I'm sorry If I can mark only one as Answer.

    By the way, to help others who are also needing this, we are going to test Okta's service to apply MFA for on-prem DCs.


  4. Chris Bunn 0 Reputation points
    2023-01-25T16:33:17.7333333+00:00

    Hi. You can enable granular MFA on any/all on-premise AD users with a third party solution UserLock.

    More information here: [https://www.isdecisions.com/products/userlock/multi-factor-authentication-mfa-active-directory.htm

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.