Microsoft Azure Multi-Factor Authentication (MFA)
The procedure describes the steps to deploy VIA to operate with Microsoft Azure Multi-Factor Authentication (MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.). This process includes the use of Aruba ClearPass Policy Manager to be able to return additional role information.
Software Requirements
The software requirements or Microsoft Azure Multi-Factor Authentication (MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.) with VIA are:
VIA 4.0 and later.
ClearPass is 6.7.9 and later, though ClearPass 6.9.1 or later is recommended.
ArubaOS 8.4 or later.
NPS functionality was tested on Windows Server 2016 and Windows Server 2019.
VIA and ArubaOS Installation and Deployment Guides
This procedure assumes your VIA environment is already configured and operational. If you require assistance with basic deployment, refer to Configuring VIA Settings on Mobility Conductor or a Standalone Controller. ArubaOS information can be found in the Aruba Support Portal.
ClearPass Installation and Deployment Guide
This document assumes your ClearPass environment is already configured and operational. If you require assistance with basic deployment, refer to the ClearPass Policy Manager Deployment Guide.
Additional Software Deployments Information
This guide requires the use of Microsoft Network Policy Server (NPS) as a RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. server. The NPS server is used as the authentication server in this workflow. The basic setup and configuration of Microsoft NPS Server is described by Microsoft at:
Integration Topology
The VIA client is terminated on the cluster of Aruba MCs. The Aruba MC will perform RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. authentication against the ClearPass cluster. ClearPass will authenticate against the on premise NPS using RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. (proxy), which has the Azure MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. NPS extension installed. The Microsoft NPS will authenticate first against the on-premise Active Directory and communicate with Azure for the secondary authentication.
Figure 1 Integration Topology Example![]()
Microsoft NPS Extension
Download the NPS Extension for Azure MFA. When this extension is downloaded, it must be installed.
NPS Azure AD Integration
Following the directions available from the Microsoft Azure product documentation site, retrieve your Directory ID from the Azure portal.
Figure 2 Retrieving the Directory ID![]()
Connect NPS Extension to Azure AD
Connecting the NPS extension requires administrative PowerShell access to execute the commands
cd ‘C:\Program Files\Microsoft\AzureMfa\Config\’ .\AzureMfaNpsExtnConfigSetup.ps1
Figure 3 Connecting the NPS extension ![]()
Microsoft NPS Configuration
Add ClearPass Policy Manager as a new RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. client to the NPS server so ClearPass is able to communicate properly with NPS.
Figure 4 Adding a RADIUS Client![]()
Connection Request Policy
Configure a connection request policy to allow authentication requests originating from ClearPass.
Figure 5 Configuring a Connection Request Policy![]()
Network Policy
Configure the network policy which will perform the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with Azure AD.
Figure 6 Configuring a Network Policy![]()
![]()
|
|
You must allow unencrypted authentication to support the Microsoft code being entered manually or delivered using SMS. |
Azure AD Connect
To install and configure Azure AD Connect:
1. Download the Azure AD Connect software.
2. Install and configure the Microsoft Azure AD Connect tool on the domain controller to connect to Azure AD and synchronize users of on-premise AD to Azure AD. During the installation, when prompted to connect to Azure AD, enter the appropriate credentials.
3. Enter the appropriate connections to connect to the on-premise AD DS systems.
Figure 9 Azure AD Sign-in Configuration![]()
![]()
User UPN
The domain configuration, can require you to configure an e-mail address containing the Azure domain-name, so users can log into Azure. See the Azure AD UserPrincipalName population section of the Microsoft Azure documentation for more information.
Figure 10 Configuring an Email Address![]()
To perform MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with Azure AD using the e-mail address, configure the LDAP mail attribute as the LDAP_ALTERNATE_LOGINID_ATTRIBUTE in the Windows Registry.
Figure 11 Setting the “LDAP_ALTERNATE_LOGINID_ATTRIBUTE Value in the Windows Registry![]()
Sync local AD with Azure AD
Force a synchronization from local AD towards Azure AD by executing following PowerShell script:
Import-Module "C:\Program Files\Microsoft Azure AD Sync\Bin\ADSync\ADSync.psd1" Start-ADSyncSyncCycle -PolicyType Initial
Validation Azure AD
After successful synchronization, the local AD users are visible in the AD Azure Portal.
Figure 12 Local AD Users in the AD Azure Portal![]()
Microsoft MFA
Microsoft supports four different types of multi-factor authentication:
Verification code delivered by SMS
Verification code delivered by the Microsoft Authenticator app
Push notification from Microsoft Authenticator app
Verification code delivered by a call from Microsoft
To start, configure the network policy which will perform the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with Azure AD. The figure below shows an example policy.
|
|
Unencrypted authentication needs to be allowed to support the Microsoft code being entered manually or delivered via SMS. |
Activation of MFA
MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. needs to be enabled in Azure AD for the user account. Once MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. is activated for a user, that user should a method of MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. and configure the Microsoft Authenticator App or phone number.
A user can choose and configure the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. method at https://account.activedirectory.windowsazure.com/Proofup.aspx.
ClearPass Configuration
When users need to download their VIA Client profile the first time, MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. is not required. When they actually connect using the VIA client, they should perform Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.. Separate services have been created in ClearPass for each logon type:
LNL VIA Profile Download Service (without MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.)
LNL VIA Connection Service (with MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.)
Different authentication profiles have been defined in the controller, each using its own authentication server group (ClearPass):
lnl_via_downl_corp_auth_profile: CPPM-RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.
lnl_via_conn_corp_auth_profile: CPPM-MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.
Both server groups contain the same ClearPass nodes as RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. servers, but to make the distinction in ClearPass between services, the NAS ID for the RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. servers of the CPPM-MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. group has been set to “MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.”. In the “LNL VIA Connection Service” on ClearPass, a check for the NAS ID has been configured.
MFA authentication source
Add the NPS servers as a new RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. authentication source in ClearPass, at Configuration > Authentication > Sources.
Figure 15 Configuring ClearPass Authentication Sources![]()
![]()
![]()
VIA Profile Download Service
The LNL VIA Profile Download Service uses the default AD authentication source for authentication.
Figure 16 Creating the LNL VIA Profile Download Service in ClearPass![]()
VIA Connection Service
The LNL VIA Connection Service performs a check on the NAS ID and it uses the NPS servers as authentication source (which will communicate with Azure for Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.).
Figure 17 Creating the LNL VIA Connection Service in ClearPass![]()
Mobility Controller Configuration
A separate authentication server group with “MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.” as NAS ID has been defined in the mobility controllers, so ClearPass can make distinction between the authentication service for a profile download and an actual connection of the VIA client.
Following authentication profiles have been configured for the VIA client, which will assign the corresponding user-roles.
lnl_via_downl_corp_auth_profile: authentication profile without MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it., used for download of the con- nection profile
lnl_via_conn_corp_auth_profile: authentication profile with MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it., used for connection of the VIA cli- ent.
Each authentication profile will assign a corresponding Aruba user-role:
lnl_via_downl_corp_role: user-role assigned for downloading the VIA profile
lnl_via_conn_corp_role: user-role assigned to connected VIA clients
Authentication servers
ArubaOS authentication servers are configured to point to ClearPass Policy Manager, not the NPS server.
Figure 18 ArubaOS Authentication Servers![]()
VIA Connection authentication profile
|
|
The authentication protocol needs to be set to PAP Password Authentication Protocol. PAP validates users by password. PAP does not encrypt passwords for transmission and is thus considered insecure. to support the Microsoft code being entered manually or delivered via SMS. |
PAP Password Authentication Protocol. PAP validates users by password. PAP does not encrypt passwords for transmission and is thus considered insecure. supports all the authentication methods of Azure MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. in the cloud: phone call, one-way text message, mobile app notification, OATH hardware tokens, and mobile app verification code.
CHAPV2 and EAP Extensible Authentication Protocol. An authentication protocol for wireless networks that extends the methods used by the PPP, a protocol often used when connecting a computer to the Internet. EAP can support multiple authentication mechanisms, such as token cards, smart cards, certificates, one-time passwords, and public key encryption authentication. support phone call and mobile app notification.
For details, refer to Microsoft Documentation on configuring an MFA NPS extension.
Figure 19 VIA Authentication Profile![]()
VIA Profile Download Authentication Profile
The profile download is a standard download. Note that this profile does not require MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it., but will require authentication against the on-premise AD server.
Figure 20 VIA Profile download authentication profile![]()
VIA Profile download user-role
This role is assigned when the VIA client performs the download of the connection profile and has the lnl_via_conn_corp_profile connection profile assigned, which defines the specific settings for VIA client and VPN/tunnel parameters.
Figure 21 VIA Profile Download User-role![]()
VIA Connection User-role
The user-role lnl_via_conn_corp_role will be assigned when a user is connected with the VIA client. Clients will receive IP addresses from the DHCP pool via-1060.
Figure 22 VIA Connection User-role![]()
Default web authentication profile
The default authentication profile used when downloading the VIA connection profile has been set to lnl_via_downl_corp_auth_profile.
Figure 23 Default Web Authentication Profile![]()
VIA Connection Profile
The specific settings of the connection are defined in lnl_via_conn_corp_profile.
|
|
The settings Use Windows credentials and Allow user to save password cannot be used because it will break the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with SMS or MS Authenticator code option. These settings will make the VIA client automatically enter the Windows username/password in the second credential prompt (which expects the SMS code or MS Authenticator code and not the Windows password). |
Figure 24 VIA Connection Profile![]()
VIA Client with Microsoft MFA Process
Profile download
While MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. may be required to download the connection profile, it is outside the scope of this document. This example does not require MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. to download the connection profile.
Microsoft MFA with SMS option
Enter the Windows usernname and password into the VIA client.
Figure 25 Logging In to the VIA Client![]()
After successful AD authentication, the NPS server will respond with a second RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. request for the MS MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. code, received via SMS. The text “Enter Your Microsoft verification cod” is sent by the Microsoft NPS server and relayed via ClearPass to the VIA client.
If SMS is selected as the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. method for the user, the Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. verification code is delivered via SMS. For example:
123456
Use this code for Microsoft verification
After entering the received verification code, authentication will succeed, and the VPN will be connected.
Figure 26 VIA Connection Complete![]()
Microsoft MFA with app code
First, enter the Windows user name and password.
Figure 27 Logging In to the VIA Client![]()
After successful AD authentication, the NPS server will respond with a second RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. request for the MS MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. code, received in the Authenticator App on smartphone. The text Enter Your Microsoft verification code is sent by the Microsoft NPS server and relayed via ClearPass to the VIA client.
Figure 28 Prompt to Enter Verification Code![]()
If the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. method selected for the user is a verification code in authenticator app, the Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. verification code is displayed in the authenticator app. After entering the code into VIA, authentication will succeed, and the VPN will be connected.
Figure 29 VIA Connection Complete![]()
Microsoft MFA with push notification
Enter he Windows user name and password.
Figure 30 Logging In to the VIA Client![]()
After successful AD authentication, a notification will pop up on the user’s smartphone.
Figure 31 Smart Phone Notification for AD Authentication![]()
After approving the notification, authentication will succeed, and the VPN will be connected.
Known Issues and Limitations
Currently, the RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. timeout is limited to 30 seconds. This means that the connection must be done quickly to ensure that the session is not closed before the authentication completes or the authentication will fail.
Was this information helpful?
Great! Thanks for the feedback
Sorry about that! How can we improve our documentation? Send your comments and suggestions!