Questions on on-prem ADFS migration to Azure MFA

%3CLINGO-SUB%20id%3D%22lingo-sub-1234922%22%20slang%3D%22en-US%22%3EQuestions%20on%20on-prem%20ADFS%20migration%20to%20Azure%20MFA%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1234922%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Experts%2C%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20of%20our%20customer%20currently%20has%20the%20below%20environment%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3ECurrently%20we%E2%80%99ve%20on-prem%20Windows%202016%20ADFS%20%E2%80%93%20SSO%20installed.%3C%2FLI%3E%3CLI%3EConditional%20access%20has%20been%20enabled%20for%20External%20users.%3C%2FLI%3E%3CLI%3EHybrid%20is%20enabled%20and%20MFA%20is%20also%20enabled%20in%20Azure%20Active%20directory.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ECurrent%20behavior%3A%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20someone%20browses%20admin.microsoft.com%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20request%20will%20hit%20on-prem%20ADFS%20and%20apply%20conditional%20access%20(If%20it%20is%20external%20users%20then%20it%E2%80%99ll%20prompt%20for%20MFA%20else%20it%20won%E2%80%99t).%20MFA%20is%20currently%20enabled%20in%20Azure%20Active%20directory.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EThe%20behavior%20we%20want%20to%20achieve%20is%2C%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20someone%20browses%20admin.microsoft.com%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20request%20should%20hit%20Azure%20AD%20MFA%20irrespective%20of%20internal%2Fexternal%20users%20and%20get%20rid%20of%20on-prem%20ADFS-SSO.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20can%20we%20achieve%20it%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20inputs%20would%20be%20of%20great%20help!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1234922%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EQuestions%20on%20on-prem%20ADFS%20migration%20to%20Azure%20MFA%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1244251%22%20slang%3D%22en-US%22%3ERe%3A%20Questions%20on%20on-prem%20ADFS%20migration%20to%20Azure%20MFA%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1244251%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F301435%22%20target%3D%22_blank%22%3E%40Newlife%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGet%20rid%20of%20on-premises%20ADFS-SSO%3F%20Not%20sure%20if%20you%20mean%20migrate%20from%20ADFS%20to%20PHS%20or%20PTA.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20want%20to%20keep%20ADFS%20and%20use%20Azure%20MFA.%20Then%20you%20need%20to%20configure%26nbsp%3BAzure%20MFA%20as%20an%20authentication%20provider%20for%20ADFS.%26nbsp%3B%20You%20should%20check%20if%20other%20services%20are%20using%20ADFS%2C%20some%20applications%20don't%20support%20certain%20Azure%20MFA%20authentication%20methods%2C%20like%20no%20prompt%20for%20TOTP%20or%20no%20notification%20to%20check%20your%20Authenticator%20app%20for%20approval.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-fs%2Foperations%2Fconfigure-ad-fs-and-azure-mfa%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fidentity%2Fad-fs%2Foperations%2Fconfigure-ad-fs-and-azure-mfa%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1264153%22%20slang%3D%22en-US%22%3ERe%3A%20Questions%20on%20on-prem%20ADFS%20migration%20to%20Azure%20MFA%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1264153%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F179479%22%20target%3D%22_blank%22%3E%40Michael%20Tang%3C%2FA%3E%26nbsp%3B-%20Thank%20you%20very%20much%20Michael%20for%20your%20inputs.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%2C%20the%20context%20is%20customer%20would%20like%20to%20get%20rid%20of%20ADFS%20and%20only%20use%20Azure%20AD%20SSO%20with%20Azure%20MFA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20advise.%20Many%20thanks%20in%20advance.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1266866%22%20slang%3D%22en-US%22%3ERe%3A%20Questions%20on%20on-prem%20ADFS%20migration%20to%20Azure%20MFA%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1266866%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F301435%22%20target%3D%22_blank%22%3E%40Newlife%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20a%20nut%20shell.%3C%2FP%3E%3CP%3EDecide%20if%20you%20want%20to%20sync%20passwords%20or%20use%20pass-thru%20authentication%20for%20Azure%20AD%20Authentication.%26nbsp%3B%20If%20your%20organization%20doesn't%20want%20to%20store%20password%20hashes%20in%20cloud%20use%20PTA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20it's%20PHS%2C%20I%20would%20first%20start%20by%20enabling%20Password%20Hash%20Sync%20in%20Azure%20AD%20Connect%20Sync%20Optional%20Features.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftutorial-phs-backup%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2Ftutorial-phs-backup%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20you%20verify%20you%20have%20Password%20Hash%20Sync%20working%20properly%20in%20the%20portal.%3C%2FP%3E%3CP%3EYou%20can%20run%20Azure%20AD%20Connect%20again%20and%20change%20the%20sign-in%20options%2C%20to%20PHS%20and%26nbsp%3B%3CSPAN%3Econvert%20from%20federated%20to%20managed%20authentication.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDepending%20on%20the%20number%20of%20objects%20you%20sync%2C%20It%20could%20be%20quick%20or%20take%20a%20bit%20of%20time%20to%20convert.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EI%20would%20take%20a%20look%20through%20this.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fhybrid%2F%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hi Experts, 

One of our customer currently has the below environment:

 

  • Currently we’ve on-prem Windows 2016 ADFS – SSO installed.
  • Conditional access has been enabled for External users.
  • Hybrid is enabled and MFA is also enabled in Azure Active directory.

 

Current behavior:

 

If someone browses admin.microsoft.com,

 

The request will hit on-prem ADFS and apply conditional access (If it is external users then it’ll prompt for MFA else it won’t). MFA is currently enabled in Azure Active directory.

 

The behavior we want to achieve is,

 

If someone browses admin.microsoft.com,

 

The request should hit Azure AD MFA irrespective of internal/external users and get rid of on-prem ADFS-SSO.

 

How can we achieve it?

 

Any inputs would be of great help!

3 Replies
Highlighted

@Newlife 

 

Get rid of on-premises ADFS-SSO? Not sure if you mean migrate from ADFS to PHS or PTA. 

 

If you want to keep ADFS and use Azure MFA. Then you need to configure Azure MFA as an authentication provider for ADFS.  You should check if other services are using ADFS, some applications don't support certain Azure MFA authentication methods, like no prompt for TOTP or no notification to check your Authenticator app for approval.

 

https://docs.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-and-azure-...

 

 

Highlighted

@Michael Tang - Thank you very much Michael for your inputs. 

 

Here, the context is customer would like to get rid of ADFS and only use Azure AD SSO with Azure MFA.

 

Please advise. Many thanks in advance. 

Highlighted

@Newlife 

 

In a nut shell.

Decide if you want to sync passwords or use pass-thru authentication for Azure AD Authentication.  If your organization doesn't want to store password hashes in cloud use PTA.

 

If it's PHS, I would first start by enabling Password Hash Sync in Azure AD Connect Sync Optional Features. 

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/tutorial-phs-backup

 

Once you verify you have Password Hash Sync working properly in the portal.

You can run Azure AD Connect again and change the sign-in options, to PHS and convert from federated to managed authentication.

 

Depending on the number of objects you sync, It could be quick or take a bit of time to convert. 

 

I would take a look through this.

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/