Light Mode

4 captures
01 Dec 2016 - 21 Aug 2025
Nov DEC Jan
01
2015 2016 2017
success
fail
About this capture
COLLECTED BY
Organization: Internet Archive
The Internet Archive discovers and captures web pages through many different web crawls. At any given time several distinct crawls are running, some for months, and some every day or longer. View the web archive through the Wayback Machine.
TIMESTAMPS
The Wayback Machine - https://web.archive.org/web/20161201104808/https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-fs/operations/configure-additional-authentication-methods-for-ad-fs
Table of contents

Shared to

Table of contents +
TOC
Collapse the table of content
Expand the table of content

Configure Additional Authentication Methods for AD FS

Bill Mathers|Last Updated: 10/6/2016

Applies To: Windows Server 2016, Windows Server 2012 R2

In order to enable multi-factor authentication (MFA), you must select at least one additional authentication method. By default, in Active Directory Federation Services (AD FS) in Windows Server 2012 R2, you can select Certificate Authentication (in other words, smart card-based authentication) as an additional authentication method.

Note

If you select Certificate Authentication, ensure that the smart card certificates have been provisioned securely and have pin requirements.

|-|-| ||Did you know that Microsoft Azure provides similar functionality in the cloud? Learn more about Microsoft Azure identity solutions.

Create a hybrid identity solution in Microsoft Azure:
- Learn about Azure Multi-Factor Authentication.
- Manage identities for single-forest hybrid environments using cloud authentication.
- Manage Risk with Additional Multi-Factor Authentication for Sensitive Applications.|

Microsoft and third-party additional authentication methods

You can also configure and enable Microsoft and third-party authentication methods in AD FS in Windows Server 2012 R2. Once installed and registered with AD FS, you can enforce MFA as part of the global or per-relying-party authentication policy.

Below is an alphabetical list of Microsoft and third-party providers with MFA offerings currently available for AD FS in Windows Server 2012 R2.

ProviderOfferingLink to learn more
GemaltoGemalto Identity & Security Serviceshttp://www.gemalto.com/identity
inWebo TechnologiesinWebo Enterprise Authentication serviceinWebo Enterprise Authentication
Login PeopleLogin People MFA API connector for AD FS 2012 R2 (public beta)https://www.loginpeople.com
Microsoft Corp.Microsoft Azure MFAWalkthrough Guide: Manage Risk with Additional Multi-Factor Authentication for Sensitive Applications (see step 3)
RSA, The Security Division of EMCRSA SecurID Authentication Agent for Microsoft Active Directory Federation ServicesRSA SecurID Authentication Agent for Microsoft Active Directory Federation Services
SafeNet, Inc.SafeNet Authentication Service (SAS) Agent for AD FSSafeNet Authentication Service: AD FS Agent Configuration Guide
SwisscomMobile ID Authentication Service and Signature ServicesMobile ID Authentication Service
SymantecSymantec Validation and ID Protection Service (VIP)Symantec Validation and ID Protection Service (VIP)

Custom Authentication Method for AD FS in Windows Server 2012 R2

We now provide instructions for building your own custom authentication method for AD FS in Windows Server 2012 R2. For more information, see Build a Custom Authentication Method for AD FS in Windows Server 2012 R2.

See Also

Manage Risk with Additional Multi-Factor Authentication for Sensitive Applications

  • IN THIS ARTICLE
  • Microsoft and third-party additional authentication methods
  • Custom Authentication Method for AD FS in Windows Server 2012 R2
  • See Also
(c) 2016 Microsoft