本地SSO IdP与Azure MFA集成方案咨询(原SDK已弃用)
Alright, since the Azure MFA SDK is no longer supported, let's walk through the most practical solutions to integrate Azure MFA as your second factor after on-prem AD SSO authentication. Given you have an Azure subscription, these approaches play nicely with your existing setup:
This is the most low-code approach, leveraging Azure's managed identity service to handle both the on-prem SSO handoff and MFA flow. Here's how to set it up:
- Federate your on-prem AD with Azure AD B2C: Configure your local SSO IdP as a SAML or OIDC identity provider in B2C. This lets users authenticate first against your on-prem system.
- Build a custom user flow: Create a B2C user flow that requires two steps: first authentication via your on-prem IdP, then Azure MFA (you can choose SMS, email, authenticator app, etc.).
- Point your apps to B2C: Update your application's authentication settings to use the B2C user flow. When users log in, they'll first go through your local SSO, then be prompted for MFA by B2C.
If you need full control over the authentication flow, you can use Azure's modern APIs instead of the deprecated SDK. Note that this requires your on-prem users to exist in Azure AD (sync via AD Connect or manual provisioning):
- Register a service principal in Azure AD: Create an app registration with permissions to manage user authentication methods (e.g.,
UserAuthenticationMethod.ReadWrite.All). Use the client credentials flow to get an access token for API calls. - Initiate MFA after local auth: Once your on-prem IdP verifies the user, call the Azure AD Graph API to send an MFA challenge (like a verification code to their registered mobile device).
- Validate the MFA response: Have the user input the verification code, then call the API again to confirm the code is valid. If successful, grant access to your application.
If you already sync your on-prem AD users to Azure AD via AD Connect, this approach is seamless:
- Set up Pass-through Authentication (PTA) and Seamless SSO: Configure AD Connect so users can log into Azure AD using their on-prem credentials without entering them twice.
- Create a conditional access policy: In Azure AD, set a policy that requires MFA for users accessing your target application(s). You can scope this to specific users, groups, or apps for granular control.
- Authenticate via Azure AD: Have your application use Azure AD for authentication. Users will first authenticate via Seamless SSO (using their on-prem AD credentials), then Azure AD will trigger MFA based on your policy.
Key Notes
- User identity matching: For all these solutions, ensure your on-prem AD users have a matching user principal name (UPN) in Azure AD. This is how Azure MFA associates the user with their registered MFA methods.
- MFA method registration: Users need to register their MFA methods (like phone number or authenticator app) in Azure AD beforehand. You can enforce this via conditional access or B2C user flows.
- Security considerations: When using custom API calls, always secure your service principal credentials and follow OAuth 2.0 best practices to avoid token leaks.
内容的提问来源于stack exchange,提问作者Janul

