RD Gateway (RDS) with NPS and MFA extension

preview_player
Показать описание
A quick overview of how the RD Gateway works with the NPS server to handle authentication and authorization for RDP users. Please let me know if you have any questions and I would be glad to help.

Here's the article I mention in the video:
Рекомендации по теме
Комментарии
Автор

Hi Nate,

Do you have a step by step video/doc how to configure MFA with AAD credentials?

suradjbajaj
Автор

Excellent explanation! I'm wondering if it's possible to use the MFA extension with NPS in an AD domain that we have NOT federated or synced with our AAD domain? (We prefer to manage Exchange Online in the cloud and so have not connected the two.) However, we'd like to use MFA with RDS...

stevedavies
Автор

Excelente! Mil y mil gracias por la explicación tan clara y facil de enteder!

CarlosBuitrago
Автор

Brilliant explanation and not just click here and there. Thank you.

just_the_job
Автор

Nate Harris for President, Nate Harris is GOD! Thanks for this and the other 2 nps / azure mfa videos!

leeross
Автор

Hello Nate, in your example did you use two different servers (One Remote Desktop Gateway Server and One NPS Server), or are all the RDG + NPS + MFA Extension Roles on a single Server?

yibambe
Автор

Hi, Nate I am keep getting below Error Please help me Reason: The remote RADIUS (Remote Authentication Dial-In User Service) server did not process the authentication request.

neeleshpathri
Автор

Really good, thank you for yor time !!!

recepozturk
Автор

Hi Nate, what if we are not using a Central NPS Server. Will MFA work with Gateway using Local NPS? I have configured everything but MFA does not trigger. RDP Connection to my rdweb servers just goes right in.

zenzei_
Автор

Hi Nate,
Do you have a good document for do the full set up? Is it possible to use the local NPS (in the RDS) or do I need to set up a Central NPS in a different server?

SalvadorAguilar-rg
Автор

Question. We have Office 365 E3 + Entra ID P1, do we need any other license?

olivermartin
Автор

All your videos are awesome! Do you know why most KBs say to have two connection request polices (to/from MFA and to/from RDG) in NPS on both servers? It works without them like how you have it configured, but I can't find any good answer on why those additional CRPs are "recommended".

scottybrown
Автор

you said that it's good practise to seperate nps and gateway but in this video, they are on the same serveR??

GurkoKurdo
Автор

Dude I felt that sigh in my bones :D fucking MS

kiroskrimsli
Автор

is it possible that the attempts do not get applied via conditional access. when i enforce conditional access and add an exclude adress, and perform nps auth on a gateway, it doesnt get applied

GurkoKurdo
Автор

Good evening Nate, do we need to disable the Network policy RD_Cap on the RD gateway server and just have it on the NPS server

WickedJ
Автор

Once NPS and the RDG is all setup, how do you turn it off or disable the feature to RDP without 2FA?

leesonnsmith
Автор

Hi. My NPS server configured for vpn connection. If I install NPS extension for configuring MFA for RD gateways, does it mean my VPN configuration will stop working? Because, now I do not use MFA for von, only for RD gateways. Thank you!

MrIvsemenyuk
Автор

Hi Nate, in the latest update of the MFA Extension Microsoft states that TOTP is supported by the extension but i really was not able to get this running. Do you have any advice to this?

supajo
Автор

Simple on screen approvals can be griefed. Unfortunately target rds users will get brute forced with approval notices on their devices. Is there a way for NPS to force OTP passcodes instead of the onscreen approval?

nobody