Forum Discussion
Mirza Dedic
Sep 22, 2021Brass Contributor
VPN Integration with Network Policy Server (NPS) RADIUS Accounting?
Hello, Looking to integrate our 3rd party VPN solution with MSFT Defender for Identity. The solution is using Microsoft's Network Policy Server (NPS) for authentication, and there are options...
Mirza Dedic
Sep 22, 2021Brass Contributor
It looks like the NPS server is not forwarding accounting messages to the DC based on wireshark data, we use the Azure MFA extensions and I read somewhere because of this it can't forward them.
Is there a way to feed this data into identity protection by other means? We have the NPS accounting logs on disk in DTS Compliant format.
In MCAS we can upload logs (https://docs.microsoft.com/en-us/cloud-app-security/discovery-docker), can we upload the NPS logs and have that tied to the "Accessed VPN Locations"?
EliOfek
Microsoft
Sep 23, 2021Sadnly no, Radius messages (properly formatted) are currently the only way.
- Mirza DedicSep 23, 2021Brass ContributorThanks Eli,
Is there a way to request feature enhancements for MDI? Would be very useful to train the system with our NPS VPN authentication logs to enhance Accessed VPN Locations reporting.- EliOfekSep 27, 2021
Microsoft
You can email MDI Feedback : AatpFeedback at microsoft com.- Benjamin BerglundSep 16, 2022Copper Contributor
EliOfek Mirza Dedic hi, do you know if this feature has been added yet? I am also looking to configure VPN integration with Defender for Identity, Cisco ASA RADIUS client and RADIUS server is NPS with NPS extension.