This message was deleted.
# citrix-netscaler
s
This message was deleted.
r
Depending on your configuration, sure. There are multiple ways to do this.
s
MFA is Azure AD with NPS configuration
r
Well, your limitation there is the dang Azure extension for NPS. You could do that with 2 NPS servers.
point NS to NPS1, where it makes the decision whether or not to send it to NPS2 which has the MFA extension.
that extension is a hack. I hate it.
s
I was looking for some article
You can do it like this (ish), but you would have NPS2 as what's the Duo Auth Proxy in this example
s
Any other way?
r
not that i'm aware of, i'm sorry. The NPS Extension for Azure is all or none.
ANY authentication made to that NPS server forwards it to Azure. You may be able to do something on the Azure side?
b
SAML would be an option
c
NFACTOR is the correct way to do what you require
Group extraction that looks for group membership as 1st factor / 2nd factor looks for group membership / 3rd factor depending on AD group membership will be MFA (azure nps extension uses Radius) or just plain old LDAP (no mfa)
✔️ 2
d
As @c4rm0 said. NFactor is the way. Group extraction first then auth based off that.
r
ah yes, that's a much better way. 🙂
c
I have a NPS server in my lab with the Azure MFA extension i will configure the Nfactor flow and share the config which should help you out
👍🏻 1
s
Ok thanks John