Azure MFA doesn't support MFA for local logon on devices. You should rather focus on hardening your environment and implementing secure administrative hosts for example
MFA for onprem domain controllers
Is it possible to have MFA integrated to onpremise AD?
Like when they login using the domain admin account they will go through MFA.
-
Johan Heyneke 81 Reputation points Microsoft Employee
2021-02-10T07:36:02.82+00:00
5 additional answers
Sort by: Most helpful
-
Daniele Bona 6 Reputation points
2021-10-02T08:08:33.063+00:00 Guys,
I think today a solution is technically possible using FIDO2 keys and the old domain "SCRIL" feature.
Also Remote Credential Guard and Protected Users are components required.Here all the details :
Please test yourself reporting feedbacks :) (I only tested in my lab , never in production so a running test might be appreciated ..)
-
Fan Fan 15,341 Reputation points Microsoft Vendor
2021-02-10T08:39:02.127+00:00 Hi,
As of July 1, 2019, Microsoft no longer offers MFA Server for new deployments.
New customers that want to require multi-factor authentication (MFA) during sign-in events should use cloud-based Azure AD Multi-Factor Authentication.
For more information , you can refer to the following link:
https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-nps-rdg
https://learn.microsoft.com/en-us/azure/active-directory/authentication/tutorial-enable-azure-mfaBest Regards,
-
Janus Bariñan 1,126 Reputation points
2021-02-13T14:59:16.627+00:00 Thanks for your answers guys. I'm sorry If I can mark only one as Answer.
By the way, to help others who are also needing this, we are going to test Okta's service to apply MFA for on-prem DCs.
-
Chris Bunn 0 Reputation points
2023-01-25T16:33:17.7333333+00:00 Hi. You can enable granular MFA on any/all on-premise AD users with a third party solution UserLock.
More information here: [https://www.isdecisions.com/products/userlock/multi-factor-authentication-mfa-active-directory.htm