Two Factor Authentication for Domain Admins


ive been asked if possible require of our domain admins use 2 factor authentication type of authentication attempt do. there technologies assist this? ideally using otp, smart cards or certificates may work well

hi,

ive been asked if possible require of our domain admins use 2 factor authentication type of authentication attempt do

as far know, there no way use 2 factor authentication kinds of authentication within domain, in authentication scenarios.

otp not supported ad domain account authentication. personally, suggest use smart card logon.

you may configure group policy settings such require smart card interactive logon , remote access logon, setting require smart card interactive logon can configured both computers , users.

as mentioned, there scenarios smart cards not applicable, instance, if implementing web sso remote desktop access, smart card not supported.

more information you:

get smart! boost network's iq smart cards

https://technet.microsoft.com/en-us/magazine/2005.01.smartcards.aspx

interactive logon: require smart card

https://technet.microsoft.com/en-us/library/cc782056(v=ws.10).aspx

using smart cards remote access

https://technet.microsoft.com/en-us/library/cc783310(v=ws.10).aspx

remote desktop web access single sign-on easier enable in windows server 2012

http://blogs.msdn.com/b/rds/archive/2012/06/25/remote-desktop-web-access-single-sign-on-now-easier-to-enable-in-windows-server-2012.aspx

best regards,

amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Management



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client