Forum Discussion

Han Valk's avatar
Han Valk
Copper Contributor
Jul 27, 2017

Hybrid Azure AD MFA with password sync, so on-prem MFA server plus cloud

I want to use Azure AD MFA for users in the following way:

Users including password hashes are synced to Azure AD using AAD Connect.

There is no ADFS trust between on-prem ADFS en Azure AD.

On-prem resources are secured using on-prem MFA server in combination with Azure AD, ADFS, Netscaler, RADIUS, etc.

Cloud resources, like Office 365 and other Azure AD integrated applications, are secured purely using the Azure AD MFA cloud service.

 

So John Doe accesses e.g. Office 365 related services and the on-prem MFA server is not used, can even be down and still John is authenticated properly because his password hash in in Azure AD and the on-prem facility is not used.

 

Now John Doe accesses an on-prem resource and MFA is done through the on-prem MFA server together with Azure AD to perform calling, texting-ing, etc.

 

Can this be done, a hybrid Azure AD MFA?

The obvious disadvantage is that there is no SSO like with ADFS, I don't want to use Seamless SSO, correct assumption?

Any other disadvantages?

 

 

 

2 Replies

Resources