A cloud-based identity and access management service for securing user authentication and resource access
Integration of RDG with AzureMFA NPS extention and Entra ID
Hello there!
I am currently trying to implement 2FA for an existing RDG environment. To do this, I've followed the steps outlined in this documentation: https://learn.microsoft.com/en-us/entra/identity/authentication/howto-mfa-nps-extension-rdg
Setup: We have a Windows terminal server farm with two terminal servers (Windows Server 2016), one connection broker (Windows Server 2022) on which the RDG is also set up, and one DC (Windows Server 2022) on which the Azure MFA NPS extension is installed.
RDG has been confirmed to work without 2FA, but after implementing the steps from the instructions, I get the following error (unfortunately, the system is in German):
Roughly translated -> "The computer X could not be connected for one of the following reasons:
- Your user account is not authorized to access the remote desktop gateway X.
- Your computer is not authorized to access Remote Desktop Gateway X.
- You are using an incompatible authentication method (e.g., the Remote Desktop Gateway may expect a smart card, but you entered a password).
Contact your network administrator for assistance.
I don't receive any notification on the MS Authenticator app set up for the User, and the error occurs immediately after entering the login details for the RDG connection, so I do not think it is a timeout issue.
In the logs for the Azure MFA Extension and Entra ID, I see the following Entrys for the login attempts:
This seems to be the same error as in these two posts:
https://learn.microsoft.com/en-us/answers/questions/818395/no-mfa-prompt-being-presented-for-nps-extension
https://learn.microsoft.com/en-us/answers/questions/2074636/azure-mfa-nps-extension-not-working
I've already tried the suggestions there, but without success. I'd really appreciate some help here. Thanks in advance!