MFA on Windows 10 over RDP

%3CLINGO-SUB%20id%3D%22lingo-sub-3271213%22%20slang%3D%22en-US%22%3EMFA%20on%20Windows%2010%20over%20RDP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3271213%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3EWe%20have%20a%20bunch%20of%20Windows%2010%20desktops%20that%20our%20admins%20use%20for%20their%20privileged%20work.%20The%20admins%20use%20their%20dedicated%20admin%20accounts%20to%20log%20onto%20them%20and%20they%20use%20RDP%20to%20make%20the%20connection.%20The%20desktops%20run%20Windows%20Enterprise%20and%20they%20are%20hosted%20on-prem.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20want%20to%20somehow%20put%20MFA%20on%20that%20RDP%20connection.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20looked%20into%20Windows%20Hello%20for%20Business%20but%20this%20doesn't%20seem%20to%20suit%20this%20particular%20scenario%20(please%20correct%20me%20if%20I'm%20wrong%20about%20this).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20could%20buy%20something%20like%20Duo%20or%20Okta%20(lol)%20to%20do%20it%2C%20but%20since%20we%20pay%20so%20much%20for%20MS%20licencing%20already%2C%20I%20was%20hoping%20that%20it%20could%20be%20done%20natively.%20For%20example%2C%20could%20it%20be%20achieved%20with%20the%20NPS%20extension%20for%20Azure%20MFA%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20suggestions%20very%20much%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3271213%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EEndpoint%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Occasional Contributor

Hello,

We have a bunch of Windows 10 desktops that our admins use for their privileged work. The admins use their dedicated admin accounts to log onto them and they use RDP to make the connection. The desktops run Windows Enterprise and they are hosted on-prem.

 

We want to somehow put MFA on that RDP connection.

 

I have looked into Windows Hello for Business but this doesn't seem to suit this particular scenario (please correct me if I'm wrong about this).

 

We could buy something like Duo or Okta (lol) to do it, but since we pay so much for MS licencing already, I was hoping that it could be done natively. For example, could it be achieved with the NPS extension for Azure MFA?

 

Any suggestions very much appreciated.

0 Replies