Forum Discussion
- DenisGEmployee
Would this article help? It is alittle bit older but the concepts are likely the same - How I did It - “Integrating Azure MFA with the BIG... - DevCentral (f5.com)
- Yesh1923Nimbostratus
hi denisg
thanks for your response , but MSFT MFA auth server is depriciated , its moved to cloud , how to i deploy below
setup with Azure MFA mobile app for authentioncation.
Start->Logon page->AD Auth--> Successful --> Azure MFA-> Advanced resource assign -> Allow / Deny
You should be able to do it with SAML and have Azure conditional access trigger the authenticator app. In any case you need things setup in Azure AD, so you might want to drop the regular AD. If you dont have Azure AD authenticator app is a no go I believe.
- Yesh1923Nimbostratus
hi boneyar
Appreciate your response, but my requirement is that. Need to connect my F5 ssl vpn once AD authenticated – Azure MFA need to prompt azure authenticator app to connect my access’s
do we get any links to configure for below
Start->Logon page->AD Authà Successful à Azure MFA-à Advanced resource assign à Allow / Deny
No, I don't believe you are going to get what you want exactly. With my route you would do AD authentication, then do Azure AD authentication and then get the Authenticator app prompt.
With Google authenticator you are able to do something like you describe:
https://loadbalancing.se/2016/07/09/setting-up-apm-with-google-authenticator/
Microsoft authenticator doesn't work standalone like that it seems, it is tied to Azure AD.
Or you must be able to show how to trigger Microsoft Authenticator without going through Azure AD Enterprise app or that RADIUS solution.
Then it becomes a Microsoft Authenticator question first and we can look how BIG-IP can hook into that.