{"id":2941,"date":"2017-04-05T03:56:21","date_gmt":"2017-04-05T03:56:21","guid":{"rendered":"http:\/\/pariswells.com\/blog\/?p=2941"},"modified":"2020-04-05T04:02:14","modified_gmt":"2020-04-05T04:02:14","slug":"azure-mfa-server-on-prem-how-to-guide","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/azure-mfa-server-on-prem-how-to-guide","title":{"rendered":"Azure MFA Server on Prem How to Guide"},"content":{"rendered":"<p>Setup MFA Server to proxy radius connections between Gateway and Radius server ( Network Policy Server )\u00a0<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image37.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb37.png\" alt=\"image\" width=\"244\" height=\"129\" border=\"0\" \/><\/a><\/p><p>Add the gateway as a Radis Client for the MFA Server<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image38.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb38.png\" alt=\"image\" width=\"244\" height=\"161\" border=\"0\" \/><\/a><\/p><p>Setup Radius Target):<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image39.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb39.png\" alt=\"image\" width=\"244\" height=\"148\" border=\"0\" \/><\/a><\/p><p>Connect Remote Desktop Gateway to MFA server<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image40.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb40.png\" alt=\"image\" width=\"243\" height=\"244\" border=\"0\" \/><\/a><\/p><p>Fix the timeout settings for the request\u00a0<\/p><p>Under Remote Radius Server open the TS Gateway Server Group. Then choose edit.<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image41.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb41.png\" alt=\"image\" width=\"244\" height=\"108\" border=\"0\" \/><\/a><\/p><p>Change seconds without response before request is considered dropped to 60 seconds.<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image42.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb42.png\" alt=\"image\" width=\"244\" height=\"211\" border=\"0\" \/><\/a><\/p><p>On the NPS server add MFA server as radius client. So I open the NPS Console on the ADC and add new radius client :<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image43.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb43.png\" alt=\"image\" width=\"244\" height=\"120\" border=\"0\" \/><\/a><\/p><p>Here I have created the MFA Radius client on the ADC:<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image44.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image_thumb44.png\" alt=\"image\" width=\"241\" height=\"283\" border=\"0\" \/><\/a><\/p><p>\u00a0Connection Request Policies Add MFA server as condition\u00a0<\/p><p><a title=\"\" href=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image421.png\" data-rel=\"lightbox-gallery-B9h7SYSF\" data-rl_title=\"\" data-rl_caption=\"\"><img loading=\"lazy\" decoding=\"async\" title=\"image\" src=\"https:\/\/markscholman.com\/wp-content\/uploads\/2014\/03\/image42_thumb.png\" alt=\"image\" width=\"422\" height=\"178\" border=\"0\" \/><\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Setup MFA Server to proxy radius connections between Gateway and Radius server ( Network Policy Server )\u00a0Add the gateway as a Radis Client for the MFA ServerSetup [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1464,2950,3185,2782,3184,1637],"class_list":["post-2941","post","type-post","status-publish","format-standard","hentry","category-research","tag-azure","tag-mfa","tag-on-prem","tag-radius","tag-server","tag-setup"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/2941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=2941"}],"version-history":[{"count":2,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/2941\/revisions"}],"predecessor-version":[{"id":4501,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/2941\/revisions\/4501"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=2941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=2941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=2941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}