THE SAFEHOUSE / JOURNAL
Identity Management · Part 3 of 7

Multi-Factor Authentication (MFA): Your Critical Second Layer of Defense

4 May 2025· 2 min read

This is the third blog in the Identity Management series, tackling Multi-Factor Authentication (MFA) — an essential security measure to protect against credential theft, phishing, and unauthorized access.

Whether you're managing systems on-prem or in the cloud, MFA is your front-line defense. Let's break it down for Windows Server, Linux, and Azure AD.

What is MFA?

Multi-Factor Authentication (MFA) requires users to present two or more verification methods to gain access. It's usually a combination of:

MFA on Windows Server

While older versions of Windows Server do not have native MFA, you can integrate MFA with RDP (Remote Desktop Protocol) and other services.

Options:

Key Integration Use-Cases: RDP access to critical servers, VPN access with NPS authentication.

Quick Guide — Azure MFA via NPS: install NPS Server and NPS Extension for Azure MFA, register your tenant using AzureMfaNpsExtnConfigSetup.ps1, and test using radtest or RADIUS clients.

MFA on Linux Server

MFA is not as "plug-and-play" on Linux, but very much possible and powerful.

Options: Google Authenticator PAM Module, Duo Unix for SSH logins, YubiKey integration via PAM.

Quick Setup — Google Authenticator for SSH:

sudo apt install libpam-google-authenticator
google-authenticator

Update /etc/pam.d/sshd:

auth required pam_google_authenticator.so

Update /etc/ssh/sshd_config:

ChallengeResponseAuthentication yes

Time-Saver: use configuration management tools (e.g., Ansible, Chef) to roll out MFA setup to multiple servers.

MFA in Azure Active Directory

This is the easiest and most powerful environment to enforce MFA at scale.

Options: Microsoft Authenticator app, SMS or Phone Call, FIDO2 Security Keys / Windows Hello.

Quick Setup: go to Azure Portal → Azure AD → Security → MFA. Enable Per-user MFA or better, use Conditional Access Policies. Set requirements: location, device platform, app sensitivity.

Bonus: use Identity Protection to trigger MFA for risky logins or unknown devices.

Quick Real-World Use Cases

Troubleshooting Common Issues

Conclusion

MFA isn't just a feature — it's a necessity. It's your low-hanging fruit to instantly boost identity security across all platforms. With minimal setup, you protect your servers, apps, and cloud environment from most credential-based attacks.

Related reading