Azure MFA extension for NPS not working after disabling NTLMv1

Oddiraju, Kiran 6 Reputation points
2022-09-22T16:25:08.387+00:00

Hello Chaps,

Yesterday we disabled NTLM 1 at the Domain level and we noticed this morning the Azure MFA plugin installed on NPS server stopped working. Tried uninstalling the plugin and install the latest version from Microsoft but that didn't help. The error message on NPS logs was "An NPS extension dynamic link library (DLL) that is installed on the NPS server rejected the connection request". We had to re-enable NTLM v1 to get the MFA working. Is there a way to force the plugin to use NTLM v2 or Kerberos for authentication? Operating system is Windows 2012 R2.

Thanks,
Kiran

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
556 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,625 questions
0 comments No comments
{count} vote

6 answers

Sort by: Most helpful
  1. Enrique Paniagua Aguilar 0 Reputation points
    2024-11-26T17:01:41.1+00:00

    An NPS extension dynamic link library (DLL) that is installed on the NPS server rejected the connection request

    Validar que el registro HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AzureMfa exista la variable OVERRIDE_NUMBER_MATCHING_WITH_OTP = FALSE

    SI esta no se encuentra se debe crear tipo string:

    regedit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AzureMfa

    OVERRIDE_NUMBER_MATCHING_WITH_OTP = FALSE

    Solucionadoooo.....

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.