https://docs.microsoft.com/en-us/azure/active-directory/auth...
It's also supported to publish behind the Azure App Proxy, avoiding the need for any port forwards at all:
https://docs.microsoft.com/en-us/azure/active-directory/app-...
https://docs.microsoft.com/en-us/azure/active-directory/auth...
It's also supported to publish behind the Azure App Proxy, avoiding the need for any port forwards at all:
https://docs.microsoft.com/en-us/azure/active-directory/app-...
Is this working well? I've tried setting this up a few weeks ago and found it to be somewhat brittle. The MFA requests would sometimes be delayed long enough that the GW would timeout. I've tested this on Windows 2022.
I will say however, the only MFA it supports is push (ie, TOTP doesn't work), and if you're not familiar with that, be aware many Android installations snooze that app and the push doesn't work unless you specifically have the app open at the time you logon.
The second there are other people with dumb passwords, or many other risk factors at play, I'd really suggest you need something doing MFA which unfortunately, MS doesn't offer out of the box on RDP.