|
cd 'C:\Program Files\Multi-Factor Authentication Server'
.\Register-MultiFactorAuthenticationAdfsAdapter.ps1
net stop adfssrv
net start adfssrv
|
bet | 5/8 | Sana | 22.07.2021 | Hajmi | 78,77 Kb. | | #15678 |
cd 'C:\Program Files\Multi-Factor Authentication Server'
.\Register-MultiFactorAuthenticationAdfsAdapter.ps1
net stop adfssrv
net start adfssrv
Configure AD FS Authentication Policy and Test Multi-Factor Authentication
Task
|
Detailed Steps
|
|
Complete these steps from an internet-connected Windows computer.
|
Enforce MFA for all external users
|
On the DC1 VM, logged on as corp\LabAdmin, open AD FS Management
Click Yes
In the left navigation pane, click Authentication Policies
In the right actions pane, click Edit Global Multi-factor Authentication…
At the bottom of the dialog box, select WindowsAzureMultiFactorAuthentication
Note: Note the various criteria which can be configured to invoke multi-factor authentication for a user at a global level.
Under Locations, select Extranet
Click OK
Leave the AD FS page open, we will need it again
|
Authenticate as an external user with multi-factor authentication and complete the fallback registration process
|
From your local machine, open Internet Explorer and navigate to https://portal.office.com
Click Continue'>Sign in
On the AD FS sign-in page, sign in as JohnF@.
Under the Multi-Factor Authentication heading, click Continue
When you receive a text message from Microsoft, reply to the text with the six-digit verification code to complete authentication.
After completing multi-factor authentication, AD FS prompts you to provide answers for a number of questions so your identity can be verified as a fallback method - supply answers for all questions and click Continue
Note: This feature is implemented by Azure Multi-Factor Authentication, but is presented seamlessly as part of the AD FS sign-in experience.
You should now be redirected to Azure AD as an authenticated user, where Azure AD will stop you to invoke its own multi-factor authentication which we configured for JohnF already - complete authentication
Close Internet Explorer
|
Add a new claim rule to supress the AAD MFA
|
| |
|
Bosh sahifa
Aloqalar
Bosh sahifa
cd 'C:\Program Files\Multi-Factor Authentication Server'
.\Register-MultiFactorAuthenticationAdfsAdapter.ps1
net stop adfssrv
net start adfssrv
|