Exchange 2016 Outlook Anywhere MFA

Mashal Khan 26 Reputation points
2021-04-30T23:02:56.533+00:00

I'm trying to implement MFA on On-Premise Exchange Server 2016, I've done some research and followings are my findings.

  • Exchange Server can't be authenticated through Network Policy Server RADIUS.
  • Any third party MFA provider aren't able to secure Outlook Anywhere / Exchange Active Sync via MFA, All are limited to Web based Apps like OWA / ECP.
  • Publishing Exchange through ADFS also secures Web Based Apps with MFA like OWA / ECP as publishing Outlook Anywhere through ADFS isn't possible.
  • Azure App Proxy also supports publishing OWA / ECP only and not Outlook Anywhere.
  • So the only possibility to have MFA in Outlook Anywhere is to use Hybrid Modern Authentication in Exchange Hybrid Deployment ?

Would be grateful for help.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,388 questions
{count} votes

Accepted answer
  1. Andy David - MVP 142.7K Reputation points MVP
    2021-05-01T14:48:27.007+00:00

    If I was doing this, then yes, I would use HMA. Its the only solution I know of that covers all the Modern Auth clients.

    https://learn.microsoft.com/en-us/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication?view=o365-worldwide#add-on-premises-web-service-urls-as-spns-in-azure-ad

    Note all the virtual directories "Protected" by HMA

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Lucas Liu-MSFT 6,161 Reputation points
    2021-05-03T05:49:09.17+00:00

    Hi @Mashal Khan ,
    The "Answers" in this post details various situations of deploying MFA in Exchange 2016, and provides reference links. You can refer to: MFA on premises Exchange 2016

    According to research on the information you porivded and another article, I agree with Andy. You could configure Exchange Server on-premises to use Hybrid Modern Authentication in Exchange Hybrid environment. For more information: Hybrid modern authentication overview and prerequisites for using it with on-premises Skype for Business and Exchange servers

    ----------

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.
    0 comments No comments

  2. Mashal Khan 26 Reputation points
    2021-05-03T12:25:42.357+00:00

    Thank You anonymous userDavid @Lucas Liu-MSFT | That answers My question.

    1 person found this answer helpful.