MFA options for RDP with RD Gateway
-
Want to put a second factor on RDP. We have an RD Gateway plus a few servers with direct access. Don't want Duo per-user pricing since we have a lot of accounts. What are the reasonable MFA options specifically for RDP?
-
@shvchnnk We're an Authlite partner, so can help if desired. They're probably the biggest non-subscription MFA service. It is a per-user/count purchased license, and requires a Yubikey/hardware token. It integrates into AD so will (by necessity) work on desktop logins also. User sees a third field on the login screen.
(we're also a Duo partner)
-
Moving this to off topic - not sure how this would relate to pfsense, unless your wanting to leverage radius on pfsense, or actually use just vpn with mfa into your network before users even auth to the remote desktop or gateway.
-
J johnpoz moved this topic from OpenVPN
-
@shvchnnk hi! There are quite a few RDP MFA solutions that integrate directly with the Windows logon process and work with both RD Gateway and standalone RDP servers.
We've been using Protectimus RDP MFA in our environment. It supports authenticator apps as well as hardware OTP tokens, and the licensing worked out better for us than some of the other options we evaluated.
One recommendation: deploy it to a small test OU first and make sure you have a break-glass or bypass account. Any solution that integrates with the Windows logon process can lock you out if something goes wrong during deployment. Hope that helps -
This post is deleted! -
Thanks! That sounds closer to what I'm looking for. Support for authenticator apps is definitely a plus. I'll check out Protectimus and see how well it fits our environment.
-
@SteveITS Thanks! I'll take a look at Authlite. The hardware token requirement isn't ideal for every user in our environment, but it definitely looks interesting.
Privacy Policy · Cookie Policy