Forum Discussion
Integrating Azure MFA and BIGIP
Hi All I have F5 on DC the customer have AzurMFA service I need Integrating that AzurMFA be the second factor with AzurPhone APP for Access to Aplication I read this article ";
but I have a little different scenario I have only BIGIP on-premises I see i need create a tunnel between BIGIP and Azure what i need to do in VPE ?
- youssef1
Cumulonimbus
Hi Igor,
You want to use MFA provide by microsoft (Phone, SMS, or Mobile App) for Strong auth.
So if you want to use this functionnality you have to an "AAA servers" and as you know, this resource is outside your internal network.
So you have to allow your Radius client to communicate with "cloud-based Azure Multi-Factor Authentication". From your F5 internel and "cloud-based Azure Multi-Factor Authentication".
Microsoft allow you to secure you communication (source IP based) and Ipsec (but i never tested it...), you have multiple choice for secure this channel. When you will setup your service you can select what you want for communication between radius services and your client (F5).
https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension
Let me know how i can help you.
regards,
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com