Remote Desktop Services with Azure MFA architecture

Marian Hercek 236 Reputation points
2021-02-22T08:44:37.22+00:00

What is minimum number of servers to deploy Remote Desktop Services (Session-based) with Azure MFA?
What is recommended server roles location?

Example: minimum number of server is 3; recommended roles location: server 1: RD Connection Broker, RD Gateway, server 2: RD Session Host, RD Web Access, server 3: NPS

Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,738 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,602 questions
{count} votes

1 answer

Sort by: Most helpful
  1. AmanpreetSingh-MSFT 56,771 Reputation points
    2021-02-22T15:27:26.04+00:00

    Hi @Marian Hercek · Thank you for reaching out.

    You need minimum 3 servers to deploy Remote Desktop Services with Azure MFA as mentioned below:

    Server 1 - Domain Controller with NPS Role and NPS Extension installed. (On-premises AD must be synced to Azure AD)
    Server 2 - RD Gateway and NPS Role.
    Server 3 - RD Sessions Host and RD Web Role.

    • NPS role must be installed on at least 2 servers, one can be DC or Member server and the other needs to be RD Gateway.
    • NPS extension cannot be installed on RD Gateway.
    • If you are going to use only one RD Sessions host, you don't need to install RD Connection Broker as it is required when multiple RD Session hosts are in a load balanced environment.

    -----------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.