{"id":3234,"date":"2018-03-29T16:23:12","date_gmt":"2018-03-29T20:53:12","guid":{"rendered":"https:\/\/www.apps4rent.com\/blog\/?p=3234"},"modified":"2020-03-06T07:02:31","modified_gmt":"2020-03-06T11:32:31","slug":"azure-mfa-selection-user-location","status":"publish","type":"post","link":"https:\/\/www.apps4rent.com\/blog\/azure-mfa-selection-user-location\/","title":{"rendered":"MFA Cloud or MFA Server \u2013 Depends on Where the Users Are"},"content":{"rendered":"<p><b>Part II: Where to setup your MFA?<\/b><\/p>\n<p style=\"text-align: justify;\">In the previous blog \u2018<a href=\"https:\/\/www.apps4rent.com\/blog\/azure-mfa-selection-what-to-secure\/\" target=\"blank\" rel=\"noopener noreferrer\">What Are You Trying to Secure with Azure MFA?<\/a>\u2019 we discussed the applications or websites that you are trying to secure with MFA. Here, let us discuss where are your users located? You can decide the <a href=\"https:\/\/www.apps4rent.com\/blog\/azure-multi-factor-authentication\/\" target=\"blank\" rel=\"noopener noreferrer\">right MFA solution<\/a> by knowing where your users are.<\/p>\n<ul>\n<li>What are you trying to secure?<\/li>\n<li><b>Where are your users?<\/b><\/li>\n<li>What are the features that you require?<\/li>\n<\/ul>\n<p style=\"text-align: justify;\">Once you have figured out what exactly you are trying to secure for implementing MFA, you will need to know where your users are located? There\u2019s a simple logic behind this.<\/p>\n<p style=\"text-align: justify;\">If your users are in the Azure Active Directory, MFA in the cloud is option for you. If your users are in the on-premises Active Directory, then you must go for MFA Server.<\/p>\n<p style=\"text-align: justify;\">However, the users can be in both Azure AD and the on-premises AD with the use of different applications (See the table below). There are specific cases and varying degrees of the user location, but the Active Directory remains central to the selection of your MFA choice.<\/p>\n<table style=\"border-collapse: collapse; width: 100%; font-size: 14px; margin-bottom: 20px;\">\n<tbody>\n<tr>\n<th style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>User Location<\/center><\/th>\n<th style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>MFA in the cloud<\/center><\/th>\n<th style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>MFA Server<\/center><\/th>\n<\/tr>\n<tr style=\"background: #f9f9f9;\">\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">Azure Active Directory<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">Azure AD and on-premises AD using federation with AD FS<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><\/td>\n<\/tr>\n<tr style=\"background: #f9f9f9;\">\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">Azure AD and on-premises AD using DirSync. Azure AD sync. Azure Connect- no password sync<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd; width: 320px;\">Azure AD and on-premises AD using DirSync. Azure Connect- with password sync<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\">On-premises Active Directory<\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<td style=\"padding: 8px; text-align: left; border-bottom: 1px solid #ddd;\"><center>Yes<\/center><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify;\">If the users are in Azure Active Directory and on-premises Active Directory using the federation with ADFS, you must opt for MFA in the cloud.<br \/>\nThe users can be in Azure AD and on-premise AD using synchronization tools like DirSync, Azure AD Connect, Azure AD Sync.<\/p>\n<p style=\"text-align: justify;\">The synchronization tools mentioned above are used in making copies of a local directory in a hybrid cloud deployment of Microsoft Exchange, for example.<\/p>\n<p style=\"text-align: justify;\">If your password is NOT synchronized along with the data, you must choose MFA in the cloud. You might not want your passwords on cloud right, which ultimately defeats the purpose of secure MFA?<\/p>\n<p style=\"text-align: justify;\">But if your password is synchronized along with the data, you might want to choose for MFA Server option, which doesn\u2019t take your data to cloud.<\/p>\n<p style=\"text-align: justify;\">Here, we have discussed about the location of users. Now let us discuss the features that you require in the concluding part (Part 3): <a href=\"https:\/\/www.apps4rent.com\/blog\/azure-mfa-selection-features\/\" target=\"blank\" rel=\"noopener noreferrer\">The features of Azure MFA \u2013 all you need to know<\/a>.<\/p>\n<p>Also see: <a href=\"https:\/\/www.apps4rent.com\/blog\/azure-vs-o365-mfa\/\"><strong>Azure MFA vs Office 365 MFA<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Part II: Where to setup your MFA? In the previous blog \u2018What Are You Trying to Secure with Azure MFA?\u2019 we discussed the applications or websites that you are trying to secure with MFA. Here, let us discuss where are your users located? You can decide the right MFA solution by knowing where your users [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":3918,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[209],"tags":[],"class_list":["post-3234","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-computing"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/posts\/3234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/comments?post=3234"}],"version-history":[{"count":0,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/posts\/3234\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/media\/3918"}],"wp:attachment":[{"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/media?parent=3234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/categories?post=3234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.apps4rent.com\/blog\/wp-json\/wp\/v2\/tags?post=3234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}