You shouldn't be exposing ADFS directly to the internet but you can do some of this you want to require MFA by location in Azure AD. We have workshops to help move off ADFS https://techcommunity.microsoft.com/t5/community-events-list/microsoft-workshops-how-to-successfully-migrate-away-from-ad-fs/m-p/3668480 & https://www.microsoft.com/en-us/security/business/identity-access/upgrade-adfs
Adfs internet / intranet
Hi we are using adfs with WAP. Internal and external Users are always connecting via WAP Top the adfs, so we can’t use Intranet ( that means a web application proxy is not present in front of AD FS) and "Extranet" in the Access rules to divide between incoming Users. Intranet/Extranet does not refer to internal or external subnets in adfs Access rules from my understanding.
What we want to achieve is that Users with a specific external IP dont need to do MFA, but for the rest of the Users with various ips it is needed.
Tried a lot of different configuraion today with specific Networks in Access rules. Mayen it is Not possible bedaure the Src ip is always the wap on adfs ?
Microsoft Security | Active Directory Federation Services
1 answer
Sort by: Most helpful
-
Mark Morowczynski 252 Reputation points Microsoft Employee
2023-01-22T15:28:06.1433333+00:00