Lately a lot of customers have been asking if we support Modern Auth for the following topology where SfB and Exchange are onprem (but are not hybrid). The answer is YES! This topology allow you to use features like O365 Multi Factor Auth (MFA) and Intune MAM with your users who are homed onprem.
The following is a high level explanation of the steps needed to enable Modern Auth for Skype for Business onpremises with AAD. For greater details, you can find them in Carolyn's blog post here. Essentially, these are the first set of steps you would need to do to set up SfB hybrid, but it is not all the steps required.
Note: If you only enable MA for one of the servers (either Exchange or SfB), but not both, your users may see multiple authentication prompts. We recommend you enable MA for both servers to get the best end user experience.
I am going to assume we start with a completely onprem deployment. So, typically, you would only have SfB onprem, Exchange onprem and AD onprem.
To enable Modern Auth on SfB onprem with AAD:
To enable Modern Auth for Exchange on-premises with AAD, you need to follow all the steps described here. Essentially, you will set up Exchange Hybrid and enable HMA but you don’t have to move any mailboxes to Exchange online.
|
Blog Post
Skype for Business Blog
3 MIN READ
Modern Auth for SfB OnPrem with AAD
Natasha Desai
Microsoft
Apr 09, 201812 Comments
- Natasha Desai
Microsoft
Chad Phillips - Yes, that topo (EXO and SfB onprem) is supported for MA. Turn on MA for EXO, then use the instructions above to turn on MA on SfB onprem.
- Chad PhillipsCopper Contributor
How about onprem sfb using exchange online?