Microsoft Azure Multi-Factor Authentication (MFA)

The procedure describes the steps to deploy VIA to operate with Microsoft Azure Multi-Factor Authentication (MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.). This process includes the use of Aruba ClearPass Policy Manager to be able to return additional role information.

Software Requirements

The software requirements or Microsoft Azure Multi-Factor Authentication (MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.) with VIA are:

VIA 4.0 and later.

ClearPass is 6.7.9 and later, though ClearPass 6.9.1 or later is recommended.

ArubaOS 8.4 or later.

NPS functionality was tested on Windows Server 2016 and Windows Server 2019.

VIA and ArubaOS Installation and Deployment Guides

This procedure assumes your VIA environment is already configured and operational. If you require assistance with basic deployment, refer to Configuring VIA Settings on Mobility Conductor or a Standalone Controller. ArubaOS information can be found in the Aruba Support Portal.

ClearPass Installation and Deployment Guide

This document assumes your ClearPass environment is already configured and operational. If you require assistance with basic deployment, refer to the ClearPass Policy Manager Deployment Guide.

Additional Software Deployments Information

This guide requires the use of Microsoft Network Policy Server (NPS) as a RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  server. The NPS server is used as the authentication server in this workflow. The basic setup and configuration of Microsoft NPS Server is described by Microsoft at:

https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/vpn- deploy-nps.

Integration Topology

The VIA client is terminated on the cluster of Aruba MCs. The Aruba MC will perform RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  authentication against the ClearPass cluster. ClearPass will authenticate against the on premise NPS using RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  (proxy), which has the Azure MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. NPS extension installed. The Microsoft NPS will authenticate first against the on-premise Active Directory and communicate with Azure for the secondary authentication.

Figure 1  Integration Topology Example

Microsoft NPS Extension

Download the NPS Extension for Azure MFA. When this extension is downloaded, it must be installed.

NPS Azure AD Integration

Following the directions available from the Microsoft Azure product documentation site, retrieve your Directory ID from the Azure portal.

Figure 2  Retrieving the Directory ID

Connect NPS Extension to Azure AD

Connecting the NPS extension requires administrative PowerShell access to execute the commands

cd ‘C:\Program Files\Microsoft\AzureMfa\Config\’ .\AzureMfaNpsExtnConfigSetup.ps1

Figure 3  Connecting the NPS extension

Microsoft NPS Configuration

Add ClearPass Policy Manager as a new RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  client to the NPS server so ClearPass is able to communicate properly with NPS.

Figure 4  Adding a RADIUS Client

Connection Request Policy

Configure a connection request policy to allow authentication requests originating from ClearPass.

Figure 5  Configuring a Connection Request Policy

Network Policy

Configure the network policy which will perform the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with Azure AD.

Figure 6  Configuring a Network Policy

 

You must allow unencrypted authentication to support the Microsoft code being entered manually or delivered using SMS.

Figure 7  Policy Overview

Azure AD Connect

To install and configure Azure AD Connect:

1. Download the Azure AD Connect software.

2. Install and configure the Microsoft Azure AD Connect tool on the domain controller to connect to Azure AD and synchronize users of on-premise AD to Azure AD. During the installation, when prompted to connect to Azure AD, enter the appropriate credentials.

Figure 8  Azure AD Credentials

3. Enter the appropriate connections to connect to the on-premise AD DS systems.

Figure 9  Azure AD Sign-in Configuration

User UPN

The domain configuration, can require you to configure an e-mail address containing the Azure domain-name, so users can log into Azure. See the Azure AD UserPrincipalName population section of the Microsoft Azure documentation for more information.

Figure 10  Configuring an Email Address

To perform MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with Azure AD using the e-mail address, configure the LDAP mail attribute as the LDAP_ALTERNATE_LOGINID_ATTRIBUTE in the Windows Registry.

Figure 11  Setting the “LDAP_ALTERNATE_LOGINID_ATTRIBUTE Value in the Windows Registry

 

Sync local AD with Azure AD

Force a synchronization from local AD towards Azure AD by executing following PowerShell script:

Import-Module "C:\Program Files\Microsoft Azure AD Sync\Bin\ADSync\ADSync.psd1" Start-ADSyncSyncCycle -PolicyType Initial

Validation Azure AD

After successful synchronization, the local AD users are visible in the AD Azure Portal.

Figure 12  Local AD Users in the AD Azure Portal

Microsoft MFA

Microsoft supports four different types of multi-factor authentication:

Verification code delivered by SMS

Verification code delivered by the Microsoft Authenticator app

Push notification from Microsoft Authenticator app

Verification code delivered by a call from Microsoft

To start, configure the network policy which will perform the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with Azure AD. The figure below shows an example policy.

Figure 13  MFA Network Policy

 

Unencrypted authentication needs to be allowed to support the Microsoft code being entered manually or delivered via SMS.

Figure 14  Policy Overview

Activation of MFA

MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. needs to be enabled in Azure AD for the user account. Once MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. is activated for a user, that user should a method of MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. and configure the Microsoft Authenticator App or phone number.

A user can choose and configure the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. method at https://account.activedirectory.windowsazure.com/Proofup.aspx.

ClearPass Configuration

When users need to download their VIA Client profile the first time, MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. is not required. When they actually connect using the VIA client, they should perform Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.. Separate services have been created in ClearPass for each logon type:

LNL VIA Profile Download Service (without MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.)

LNL VIA Connection Service (with MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.)

Different authentication profiles have been defined in the controller, each using its own authentication server group (ClearPass):

lnl_via_downl_corp_auth_profile: CPPM-RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources. 

lnl_via_conn_corp_auth_profile: CPPM-MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.

Both server groups contain the same ClearPass nodes as RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  servers, but to make the distinction in ClearPass between services, the NAS ID for the RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  servers of the CPPM-MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. group has been set to “MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.”. In the “LNL VIA Connection Service” on ClearPass, a check for the NAS ID has been configured.

MFA authentication source

Add the NPS servers as a new RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  authentication source in ClearPass, at Configuration > Authentication > Sources.

Figure 15  Configuring ClearPass Authentication Sources



VIA Profile Download Service

The LNL VIA Profile Download Service uses the default AD authentication source for authentication.

Figure 16  Creating the LNL VIA Profile Download Service in ClearPass





VIA Connection Service

The LNL VIA Connection Service performs a check on the NAS ID and it uses the NPS servers as authentication source (which will communicate with Azure for Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.).

Figure 17  Creating the LNL VIA Connection Service in ClearPass




 

 

Mobility Controller Configuration

A separate authentication server group with “MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it.” as NAS ID has been defined in the mobility controllers, so ClearPass can make distinction between the authentication service for a profile download and an actual connection of the VIA client.

Following authentication profiles have been configured for the VIA client, which will assign the corresponding user-roles.

lnl_via_downl_corp_auth_profile: authentication profile without MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it., used for download of the con- nection profile

lnl_via_conn_corp_auth_profile: authentication profile with MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it., used for connection of the VIA cli- ent.

Each authentication profile will assign a corresponding Aruba user-role:

lnl_via_downl_corp_role: user-role assigned for downloading the VIA profile

lnl_via_conn_corp_role: user-role assigned to connected VIA clients

Authentication servers

ArubaOS authentication servers are configured to point to ClearPass Policy Manager, not the NPS server.

Figure 18  ArubaOS Authentication Servers

VIA Connection authentication profile

 

The authentication protocol needs to be set to PAP Password Authentication Protocol. PAP validates users by password. PAP does not encrypt passwords for transmission and is thus considered insecure. to support the Microsoft code being entered manually or delivered via SMS.

PAP Password Authentication Protocol. PAP validates users by password. PAP does not encrypt passwords for transmission and is thus considered insecure. supports all the authentication methods of Azure MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. in the cloud: phone call, one-way text message, mobile app notification, OATH hardware tokens, and mobile app verification code.

CHAPV2 and EAP Extensible Authentication Protocol. An authentication protocol for wireless networks that extends the methods used by the PPP, a protocol often used when connecting a computer to the Internet. EAP can support multiple authentication mechanisms, such as token cards, smart cards, certificates, one-time passwords, and public key encryption authentication.  support phone call and mobile app notification.

For details, refer to Microsoft Documentation on configuring an MFA NPS extension.

Figure 19  VIA Authentication Profile

VIA Profile Download Authentication Profile

The profile download is a standard download. Note that this profile does not require MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it., but will require authentication against the on-premise AD server.

Figure 20  VIA Profile download authentication profile

VIA Profile download user-role

This role is assigned when the VIA client performs the download of the connection profile and has the lnl_via_conn_corp_profile connection profile assigned, which defines the specific settings for VIA client and VPN/tunnel parameters.

Figure 21  VIA Profile Download User-role

 

VIA Connection User-role

The user-role lnl_via_conn_corp_role will be assigned when a user is connected with the VIA client. Clients will receive IP addresses from the DHCP pool via-1060.

Figure 22  VIA Connection User-role

Default web authentication profile

The default authentication profile used when downloading the VIA connection profile has been set to lnl_via_downl_corp_auth_profile.

Figure 23  Default Web Authentication Profile

VIA Connection Profile

The specific settings of the connection are defined in lnl_via_conn_corp_profile.

 

The settings Use Windows credentials and Allow user to save password cannot be used because it will break the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. with SMS or MS Authenticator code option. These settings will make the VIA client automatically enter the Windows username/password in the second credential prompt (which expects the SMS code or MS Authenticator code and not the Windows password).

Figure 24  VIA Connection Profile

VIA Client with Microsoft MFA Process

Profile download

While MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. may be required to download the connection profile, it is outside the scope of this document. This example does not require MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. to download the connection profile.

Microsoft MFA with SMS option

Enter the Windows usernname and password into the VIA client.

Figure 25  Logging In to the VIA Client

After successful AD authentication, the NPS server will respond with a second RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  request for the MS MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. code, received via SMS. The text “Enter Your Microsoft verification cod” is sent by the Microsoft NPS server and relayed via ClearPass to the VIA client.

If SMS is selected as the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. method for the user, the Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. verification code is delivered via SMS. For example:

123456
Use this code for Microsoft verification

After entering the received verification code, authentication will succeed, and the VPN will be connected.

Figure 26  VIA Connection Complete

Microsoft MFA with app code

First, enter the Windows user name and password.

Figure 27  Logging In to the VIA Client

 

After successful AD authentication, the NPS server will respond with a second RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  request for the MS MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. code, received in the Authenticator App on smartphone. The text Enter Your Microsoft verification code is sent by the Microsoft NPS server and relayed via ClearPass to the VIA client.

Figure 28  Prompt to Enter Verification Code

If the MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. method selected for the user is a verification code in authenticator app, the Microsoft MFA Multi-factor Authentication. MFA lets you require multiple factors, or proofs of identity, when authenticating a user. Policy configurations define how often multi-factor authentication will be required, or conditions that will trigger it. verification code is displayed in the authenticator app. After entering the code into VIA, authentication will succeed, and the VPN will be connected.

Figure 29  VIA Connection Complete

Microsoft MFA with push notification

Enter he Windows user name and password.

Figure 30  Logging In to the VIA Client

After successful AD authentication, a notification will pop up on the user’s smartphone.

Figure 31  Smart Phone Notification for AD Authentication

After approving the notification, authentication will succeed, and the VPN will be connected.

Known Issues and Limitations

Currently, the RADIUS Remote Authentication Dial-In User Service. An Industry-standard network access protocol for remote authentication. It allowsauthentication, authorization, and accounting of remote users who want to access network resources.  timeout is limited to 30 seconds. This means that the connection must be done quickly to ensure that the session is not closed before the authentication completes or the authentication will fail.