Hi @Marian Hercek · Thank you for reaching out.
You need minimum 3 servers to deploy Remote Desktop Services with Azure MFA as mentioned below:
Server 1 - Domain Controller with NPS Role and NPS Extension installed. (On-premises AD must be synced to Azure AD)
Server 2 - RD Gateway and NPS Role.
Server 3 - RD Sessions Host and RD Web Role.
- NPS role must be installed on at least 2 servers, one can be DC or Member server and the other needs to be RD Gateway.
- NPS extension cannot be installed on RD Gateway.
- If you are going to use only one RD Sessions host, you don't need to install RD Connection Broker as it is required when multiple RD Session hosts are in a load balanced environment.
-----------------------------------------------------------------------------------------------------------
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.