Azure MFA Authentication Cloud Based with Cisco Remote Access VPN

LateNaite used Ask the Experts™
Just wondering if we implement Microsoft Azure Multi-Factor Authentication (2MFA) via O365 Cloud based with Cisco Anyconnect VPN for remote authentication, is the Radius/NPS Integration done using the external interface or internal interface?

Usually with Cisco LDAPS authentication (through port 636 for Secure LDAP authentication) and Radius authentication, this is done through the internal interface so not too concern about the security and communication among the ASA and Radius server.

But if we go with Azure MFA Cloud based, just wondering how this will work and if it will be routed through the internet and how secure is it.  Is it through certificate or will a VPC needed as a prerequisite.

Thank you!
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Shreedhar EtteTechnical Manager
Top Expert 2010

The connection from Azure MFA to your infrastructure communication will be external.

Please refer below article for the requirment to implement MFA for Cisco ASA VPN:
LateNaiteCEO and Founder


Hi Shreedhar, this doesn't talk about how the NPS extension talks to the Cisco ASA VPN.  If we have Cloud based Azure, is the radius/NPS communication going over the outside interface to authenticate users?  When on-premise, this is all done internally on the inside interface, when it is fine but on the outside, there is a security concern there.
CEO and Founder
We're going a different route with this.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial