Forum Discussion

ATSI's avatar
ATSI
Copper Contributor
Aug 02, 2021

Windows 365 / Azure Virtual Desktop MFA Not Being Enforced?

Was doing some tests today using an AAD user that has enforced MFA:

 

  • Connecting to AVD VM using MFA Enabled AAD credentials... doesn't work
    • VM using the AAD auth preview
    • If I disable MFA enforcement it works fine
  • Connecting to a Windows 365 PC using MFA Enabled AAD credential... works
    • Brand new VM spun up today
    • Works with MFA enforcement and without

For the actual RD session that connects via RD Gateway, it doesn't look like MFA is in use.  And, for W365, it looks like it's actually bypassing the MFA enforcement.

 

Is this accurate?  

    • ATSI's avatar
      ATSI
      Copper Contributor

      Steven DeQuincey 

       

      I've tested this quite a bit now...

       

      For a WVD Windows 10 VM:

      • MFA disabled, I can login without issue
      • MFA Enabled, I cannot login
      • Conditional MFA Enabled, I cannot login

      For a Windows 365 VM:

      • I can login regardless of whether or not MFA is enabled, a MFA prompt doesn't happen

      I'm comparing this to local RDS or an RDS in Azure where authentication can be configured to require MFA, forcing a prompt on the Authenticator app to connect. I'm pretty sure W365 is bypassing MFA and am under the impression RD Gateway in WVD/W365 doesn't actually support MFA.  

Resources