Lately a lot of customers have been asking if we support Modern Auth for the following topology where SfB and Exchange are onprem (but are not hybrid). The answer is YES! This topology allow you to use features like O365 Multi Factor Auth (MFA) and Intune MAM with your users who are homed onprem.
The following is a high level explanation of the steps needed to enable Modern Auth for Skype for Business onpremises with AAD. For greater details, you can find them in Carolyn's blog post here. Essentially, these are the first set of steps you would need to do to set up SfB hybrid, but it is not all the steps required.
Note: If you only enable MA for one of the servers (either Exchange or SfB), but not both, your users may see multiple authentication prompts. We recommend you enable MA for both servers to get the best end user experience.
I am going to assume we start with a completely onprem deployment. So, typically, you would only have SfB onprem, Exchange onprem and AD onprem.
To enable Modern Auth on SfB onprem with AAD:
To enable Modern Auth for Exchange on-premises with AAD, you need to follow all the steps described here. Essentially, you will set up Exchange Hybrid and enable HMA but you don’t have to move any mailboxes to Exchange online.
|
Updated Apr 09, 2018
Version 1.0Natasha Desai
Microsoft
Joined June 26, 2017
Skype for Business Blog
Follow this blog board to get notified when there's new activity