Thursday, January 7, 2016

Home / Azure MFA–Publishing MFA Portals using Web Applicaion Proxy

Azure MFA–Publishing MFA Portals using Web Applicaion Proxy

 

The goal is to publish on premises Microsoft Multi Factor Authentication (MFA) server portals using Web Application Proxy Service (not Azure Application Proxy!) The Microsoft MFA has the following 3 portals:

1. User Portal - The User Portal section allows the administrator to install and configure the Multi-Factor Authentication User Portal.

2. Web Service SDK - The Web Service SDK section allows the administrator to install the Multi-Factor Authentication Web Service SDK.

3. Mobile App - The Mobile App section allows the administrator to configure settings for the Mobile App.  There is also a Mobile App Web Service which needs to be installed to support mobile app activations.

At the end of the configuration, my goal is to provide a single direction URL for User Portal, Web Service SDK and Mobile App shown below:

 

image

SS

Santhosh Sivarajan

Microsoft MVP · Identity & Cybersecurity Architect

Santhosh has 30+ years of hands-on enterprise experience in Identity and Access Management, Microsoft Entra ID, Active Directory, Microsoft 365 and Zero Trust architecture. He is the author of two books on Windows Server and security, and leads consulting, assessments and training at SAG Business Group.

13 comments:

Hi. Have you managed to get this working

Yes. Ran in to any issues? What is the issue?

Sorry I thought you said you were going to make a guide.

The ADFS servers sit behind the WAP servers. Where have you installed the user portal? and how have you published this to the outside?

Interesting. I had step-by-step instructions on configuring this. Somehow it got deleted. I will re-post it as soon as I can.

I have dedicated machines for User Portal. Then I published it through WAP. Technically, it doesn’t matter. It is just a URL you can publish it from anywhere.
If you have more than on web services/site/directories running on an IIS, you need to use IIS re-direction.

This comment has been removed by the author.
This comment has been removed by the author.

Hi Santhosh,
How is that different if we publish the MFA portals using AAD Application proxy?

You can publish MFA or any on-premises application using AADProxy. However, most of the enterprise customers are already using ADFA/WAP. So it is easier fro them to add another URL (MFA Portal) to existing WAP

I was very encouraged to find this site. I wanted to thank you for this special read. I definitely savored every little bit of it and I have you bookmarked to check out new stuff you post. Russia

"If you’re looking for a team of professionals to create your perfect 2D/3D animation, then Prolific Studio can provide you with a satisfactory video animation service. We provide more than a decade worth of experience in social media animations, corporate video animations, cartoon animations, and a variety of other 2D/3D animations. Are you located in San Francisco and want to give your brand the perfect animation video? Call our san francisco animation studio and get the best deals for animation services.

Blue Mountain Event Pix specializes in photo booth rental services, including custom photo booth frames, for various events like weddings, corporate gatherings, and parties. They emphasize quality and affordability, offering high-resolution cameras and a range of props, backdrops, and photo booth frames for a customized experience. Their services include instant digital sharing and custom prints, aiming to enhance the fun and memory-making aspects of events with their unique photo booth frames.

Post a Comment

Popular Posts
Workstation Trust Relationship Issue Issue: You receive the following error message, when you try to login to the domain.  The security database on the server does not have ... ADMT Service Account - Permission and Configuration The ADMT service account needs to have proper permission in source and target domains.  You don’t need to use 2 separate accounts.  You can ... My First Peek into Microsoft Exchange 2010 By Santhosh Sivarajan Before I really dive into Exchange 2010, I thought I would install and play with it first. I took some screen shots and notes during the ins... ObjectSID and Active Directory What is an objectSID in Active Directory? When a new object is created in Active Directory, Domain Controller assigns a unique value used ... AD Group Report - List Group Members in Active Directory–PowerShell Script Updated Script - http://portal.sivarajan.com/2011/10/search-ad-collect-local-admin-group.html Script #1 This script... Add Users to a Group–PowerShell Script Purpose – Add users to a group from an input file – PowerShell V2 Script.  Input file – Input file (Users.csv) contains samAccountName in... User Account Migration and Merging – Part I (ADMT) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM pre-creating user account ... User Account Migration and Merging – Part II (Quest Migration Manager) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM Pre-creating user account in... Delete Stale or Inactive Computer Accounts from Active Directory Here is an easy way to identify and delete inactive or stale computers in an Active Directory environment.  Using the dsquery command you c... Converting PowerShell (PS1) to EXE / Standalone Application As we know, there many applications available to convert a PowerShell file to a standalone executable file.  Based on my experience, PowerSh...