Secure your Infrastructure with Azure Multi-Factor Authentication Server Online Conference June 17 th and 18 th 2015
Prabhat Nigam CTO Golden Five Consulting CEO - LAEXUG Foundation 18 years in IT Worked for All IT Giants 3xMVP, Blogger, Speaker, Author, Father, Husband Blog: MSExchangeguru.com Website: GoldenFiveConsulting.com Email: Prabhat.Nigam@GoldenFive.net Twitter: @PrabhatNigamXHG Phone: +1-609-738-728 LinkedIn:https://www.linkedin.com/ in/prabhat-nigam-42644a8/
Agenda Identifying the Security Risk Security Options Azure Multi-Factor Authentication Secure Your Infrastructure with Azure MFA
Security Analysis shared By Microsoft 160 million customer records compromised 140-200+ days between infiltration and detection 87% of senior managers admit using personal accounts for work 50% year over year growth in electronic data Ever-evolving industry standards across geographies
Recent Cyber Attacks My Doom A Virus which caused $38.5 Billion Financial damage Year 2016 witnessed frequent cyber-attacks Increased by 400 hundred percent Malware Attack nearly doubled 8.19 billon Cesar Ransomware Witnessed by me $18000 Ransom paid by Hospital in my city Ransomware or Crypto Virus or Crypto-Locker Chief of Police wrote this: http://www.officer.com/article/12304582/alert-ransomware-and-crypto-virus
Reality Check of Cyber Attack How many here has been experienced of cyber attack? Or Your Organization has been attacked. Let us check here. http://map.norsecorp.com/#/
Security Options No Internet DMZ VPN Enforce Paraphrase Password MFA or Two Factor Authentication
Multi-Factor Authenticationoptions OCTA MFA AWS MFA RSA Token Symantec VIP CA Advance authentication Duo Two Factor Authentication Eset Two Factor Authentication Azure MFA
Azure MFA Options There are two versions of Azure MFA Office 365 version On-Premise version Azure Multi-Factor Authentication Server
Azure MFA O365 Version Conditions User Location (IP range) Device state User group Risk Allow access Or Enforce MFA per user/per app Block access MFA
Download Azure MFA Server 1. Login to Azure 2. Add either of these licenses Azure Multi-Factor Authentication, Azure Active Directory Premium, Enterprise Mobility Suite Enterprise Cloud Suite. 3. Expand the Active Directory Clicked on Configure browse down to multifactor Authentication Clicked on Manage Service Settings 4. Click on Go to the Portal 5. Click on Downloads then on Download
Applications Required to Secure Infrastructure We need to deploy the following: On Premises Server 1 with the following: Active Directory Federation Services (ADFS) Azure Multi-Factor Authentication (AMFA) Server 2 with the following: Remote Desktop WEB (RDW) Remote Desktop Gateway (RDG) Network Policy Server (NPS) Web Application Proxy (WAP).
Configure Secure Office with Azure MFA 1 We need to configure the following: Obtain an SSL Cert with the private key Install & Configure Azure MFA Server Install & Configure ADFS. Also configure to use Azure MFA Install & Configure Web Application Proxy to connect to ADFS Server Install and Configure RDWeb, RDGateway and Network Policy Server for Radius pointing to Azure MFA Configure Azure MFA for Radius Server Configure Certificate at all the places.
Configure Secure Office with Azure MFA 2 Configure external dns for ADFS url to Point to WAP Server Point your RDWeb Portal and RDGateway DNS to the same WAP server. In ADFS configure the following: Add Relying party trusts for OWA and ECP and add claims. Add Non-Claims aware Relying party Trust in the ADFS server Add Office 365 relying party Trust and add claims. Configure WAP all the External URL except OWA/ECP Configure Exchange server for Azure MFA Configure Application for the RDWeb Portal Page.
Azure MFA Server Architecture MFA Allow access Or Block access 4 Azure AD and MFA Token server RDWEB will send direct request to MFA Server Enforce MFA per user/per app 3 Azure MFA Exchange User WAP RDW RDG 1 AD FS 2 AD DC
Azure MFA Server: Known Issues Twice MFA Prompt for MAC Users Expected behavior Work around is to add cache NPS Database Corruption Uninstall and Reinstall NPS, RDGateway Restart the server then reconfigure everything. OWA Showing Blank Page Configure OWA Redirection in IIS at Default Web Site OWA Auth Unable to connect to the Master MFA server Add MFA computer object in PhoneFactor Admins Group membership Unable to Open Application on Non-IE Browsers Use correct parameter with the cmd Set-RDSessionCollectionConfiguration Thin PC Getting Certificate popup Add Certificate thumbprint using GPO
Takeaways Reasons to secure your Infrastructure? Ways to Secure your Infrastructure? How can we Use Azure MFA to Secure whole Infrastructure Places to troubleshoot Azure MFA
References http://msexchangeguru.com/2017/01/16/unable-to-downloadazuremfa/ http://msexchangeguru.com/2017/01/28/azure-mfa1/ http://msexchangeguru.com/2017/01/28/azure-mfa2/ http://msexchangeguru.com/2017/02/02/mfa-for-rds1/ http://msexchangeguru.com/2017/02/02/mfa-for-rds2/ http://msexchangeguru.com/2016/12/09/wap-adfs-mfa-part-1/ http://msexchangeguru.com/2016/12/09/wap-adfs-mfa-part-2/
Connect For More Twitter: @MSExchangeGuru @PrabhatNigamXHG Facebook Group: Microsoft Exchange 2016 Microsoft Exchange Server 2019 YouTube: MSExchangeGuru Channel Yammer: Microsoft Exchange Server 2019 LinkedIn: Microsoft Exchange Server Microsoft Exchange Server 2013 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 User Groups: LAEXUG LACIUG LAEXUG_ALL_IT
Merci mulțumesc धन यव द σας ευχαριστώ
Stay tuned for more great sessions