{"id":3201,"date":"2018-04-02T16:27:22","date_gmt":"2018-04-02T20:57:22","guid":{"rendered":"https:\/\/www.apps4rent.com\/blog\/?p=3201"},"modified":"2020-03-06T06:59:34","modified_gmt":"2020-03-06T11:29:34","slug":"azure-mfa-selection-what-to-secure","status":"publish","type":"post","link":"https:\/\/www.apps4rent.com\/blog\/azure-mfa-selection-what-to-secure\/","title":{"rendered":"What Are You Trying to Secure With Azure MFA?"},"content":{"rendered":"<p><b>Part I \u2013 Where to setup your MFA: In cloud or on-premises Server<\/b><\/p>\n<p style=\"text-align: justify;\">As discussed in an earlier blog post \u2018<a title=\"Azure Multi-Factor Authentication (MFA) Overview\" href=\"https:\/\/www.apps4rent.com\/blog\/azure-multi-factor-authentication\/\" target=\"blank\" rel=\"noopener noreferrer\">Azure Multi-Factor Authentication (MFA) Overview<\/a>\u2019, Multi Factor Authentication (MFA) is an important tool to help safeguard your data and applications, all while meeting the user demand of a simple sign-in process. Microsoft\u2019s cloud offering Azure also provides MFA service. But the question is, where can you execute the MFA service with Azure?<\/p>\n<p style=\"text-align: justify;\">There are two options where a customer can choose to implement their MFA with Azure:<\/p>\n<ul>\n<li>MFA Server \u2013 An on-premise solution<\/li>\n<li>MFA in the cloud \u2013 A cloud-based solution maintained by Microsoft<\/li>\n<\/ul>\n<p><b>What will you choose?<\/b><br \/>\nThere are three questions you need to answer before you opt for either of these two options:<\/p>\n<ul>\n<li><b>What are you trying to secure?<\/b><\/li>\n<li>Where are your users?<\/li>\n<li>What are the features that you require?<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">You are implementing MFA because you want an exact thing to be secure. Is it an application? Or is it a website? Or a payment gateway? Maybe a financial application? Even a remote access system? It can be anything which requires added layers of security to the thing which you\u2019re securing.<\/p>\n<p style=\"text-align: justify;\">The first and foremost question always remains: what are you trying to secure? Based on that, you can determine the best method you can implement for the Azure MFA.<\/p>\n<p>Please have a look at the table below:<\/p>\n<table style=\"border-collapse: collapse; width: 100%; font-size: 14px; margin-bottom: 20px;\">\n<tbody>\n<tr>\n<th style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>What are you trying to secure<\/center><\/th>\n<th style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>MFA in cloud<\/center><\/th>\n<th style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>MFA Server<\/center><\/th>\n<\/tr>\n<tr>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">First-party Microsoft apps<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<\/tr>\n<tr style=\"background: #f9f9f9;\">\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">Saas apps in the App gallery<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd; width: 320px;\">Web applications published through Azure AD App Proxy<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><\/td>\n<\/tr>\n<tr style=\"background: #f9f9f9;\">\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd; width: 320px;\">IIS applications not published through Azure AD App Proxy<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">Remote access such as VPN, RDG<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><b>First-party Microsoft apps<\/b><\/p>\n<p style=\"text-align: justify;\">The first-party applications from Microsoft can be secured in both MFA in the cloud as well as Server. The first-party applications are Microsoft\u2019s own direct offerings like Office, Project, Publisher, Outlook Web App, Calendar and many more.<\/p>\n<p><b>SaaS applications in the app gallery<\/b><\/p>\n<p style=\"text-align: justify;\">The SaaS applications such as Office 365, Box and Salesforce in the Azure Active Directory application gallery can be secured only with MFA in the cloud, and not with the MFA Server.<\/p>\n<p><b>Web applications published through Azure AD App Proxy <\/b><\/p>\n<p style=\"text-align: justify;\">The web applications which are published through Azure Active Directory App Proxy, they can be secured only with MFA in the cloud, and not with the MFA Server.<\/p>\n<p><b>IIS applications not published through Azure AD App proxy<\/b><\/p>\n<p style=\"text-align: justify;\">IIS applications that are not published through Azure AD App Proxy, only that applications can be accessed with the MFA Server.<\/p>\n<p><b>Remote access like VPN, RDG<\/b><\/p>\n<p style=\"text-align: justify;\">Remote access like Virtual Private Networks and Remote Desktop Gateway can be secured in both MFA in the cloud as well as MFA Server.<\/p>\n<p style=\"text-align: justify;\">Since you\u2019ve decided what you are trying to secure, let us see the next question in the next blog &#8216;<a href=\"https:\/\/www.apps4rent.com\/blog\/azure-mfa-selection-user-location\/\" target=\"blank\" rel=\"noopener noreferrer\">MFA Cloud or MFA Server \u2013 Depends on Where the Users Are<\/a>.&#8217;<\/p>\n<p><strong>Also see:<\/strong> <a href=\"https:\/\/www.apps4rent.com\/blog\/azure-vs-o365-mfa\/\">Azure MFA vs Office 365 MFA\u00a0<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Part I \u2013 Where to setup your MFA: In cloud or on-premises Server As discussed in an earlier blog post \u2018Azure Multi-Factor Authentication (MFA) Overview\u2019, Multi Factor Authentication (MFA) is an important tool to help safeguard your data and applications, all while meeting the user demand of a simple sign-in process. Microsoft\u2019s cloud offering Azure [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":3913,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[209],"tags":[],"class_list":["post-3201","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-computing"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/posts\/3201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/comments?post=3201"}],"version-history":[{"count":0,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/posts\/3201\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/media\/3913"}],"wp:attachment":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/media?parent=3201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/categories?post=3201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/tags?post=3201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}