-
User guide: Enabling multi-factor authentication
Enabling Multi-Factor Authentication (MFA) significantly increases the security of user accounts when accessing Microsoft Azure and Microsoft 365 online services. The following user guide will help to set up one of the following authentication methods. Three options are available to authenticate with the second factor:
-
Enforce Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) provides a high level of protection for identities in the cloud. The user must identify himself with a second factor in addition to the password. Without this second factor, access to cloud apps are prevented. The feature “Azure AD Conditional Access” can be used to enforce multi-factor authentication. At least two of the following authentication methods then become mandatory:
-
Azure AD Connect: Synchronize Directory Extensions
A local Active Directory can have directory extensions. For example, when installing Microsoft Exchange 15 extension attributes are created in Active Directory. Die Werte dieser Verzeichniserweiterungen werden nicht mit Azure AD Connect synchronisiert. Wenn diese Werte in Azure AD benötigt werden, muss Azure AD Connect so konfiguriert werden, dass dies geschieht.
-
Azure AD Connect: High Availability with Staging Mode
The ability to run an Azure AD Connect installation in staging mode, prepared identically by importing the active configuration, allows a High Availability solution to be created for Azure AD synchronization with minimal effort. In case of a disaster recovery of the Azure AD Connect service, only the staging mode on the prepared server can be deactivated due to the high availability. The synchronization from Active Directory to Azure Active Directory continues to work seamlessly.
-
Azure AD Connect: Migration from Passthrough Authentication (PTA) to Password Hash Synchronization (PHS)
Migrating from Passthrough Authentication to Password Hash Sync (PHS) synchronizes passwords from the on-premises Active Directory instance to Azure AD. This is a considerable gain in convenience for users. From now on, they can sign in with the same credentials (user name, password and optionally with multi-factor authentication).This increases productivity and at the same time reduces user support costs.