cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5898
Views
0
Helpful
3
Replies

Cisco Anyconnect with on-premises AD and Microsoft Authenticator MFA

dganta
Level 1
Level 1

HI,

 

We are looking to integrate our Cisco anyconnect with Microsoft MFA for secondary authentication with primary authentication being on-premises AD, we are as of now integrated it with DUO MFA for secondary authentication and want to migrate that to Microsoft MFA, however cannot see the document for the same anywhere can we  configure this  without NPS extension just using on-premises AD

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

AnyConnect, acting as the VPN client to a headend ASA or FTD device, cannot currently authenticate directly with Microsoft MFA, either as primary or secondary authentication. It can authenticate via SAML to Azure AD and then Azure can be set to use Microsoft MFA. Similarly it can use the NPS extension as you alluded to.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

AnyConnect, acting as the VPN client to a headend ASA or FTD device, cannot currently authenticate directly with Microsoft MFA, either as primary or secondary authentication. It can authenticate via SAML to Azure AD and then Azure can be set to use Microsoft MFA. Similarly it can use the NPS extension as you alluded to.

dganta
Level 1
Level 1

Thank you Marvin for the reply. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: