> For the complete documentation index, see [llms.txt](https://docs.parallels.com/landing/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.parallels.com/landing/ras-admin-guide/v21-de-de/verbindungs-und-authentifizierungseinstellungen/multifaktor-authentifizierung/verwenden-von-radius/konfigurieren-von-azure-mfa.md).

# Konfigurieren von Azure MFA

Bevor Sie sich mit diesem Abschnitt beschäftigen, lesen Sie bitte den folgenden wichtigen Hinweis.

**Hinweis:** Ab dem 1. Juli 2019 wird Microsoft MFA Server nicht mehr für Neuimplementierungen anbieten. Neukunden, die eine Multi-Faktor-Authentifizierung von ihren Benutzern verlangen möchten, sollten die Cloud-basierte Azure Multi-Faktor-Authentifizierung verwenden. Bestehende Kunden, die MFA Server vor dem 1. Juli aktiviert haben, können die neueste Version und zukünftige Updates herunterladen und wie gewohnt Aktivierungsdaten generieren. [https://docs.microsoft.com/de-de/azure/active-directory/authentication/howto-mfaserver-deploy](https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfaserver-deploy).\
Für neue Implementierungen wird empfohlen, die Azure NPS-Erweiterung [https://docs.microsoft.com/de-de/azure/active-directory/authentication/howto-mfa-nps-extension](https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension) oder den Azure MFA Service zusammen mit der SAML-Konfiguration in RAS zu verwenden.

**Konfigurieren von Azure MFA**

Abhängig vom Standort des Benutzers gibt es vier Szenarien für den Cloud-MFA-Service:

| **Benutzerstandort**                                                                                              | **MFA in der Cloud** | **MFA-Server** |
| ----------------------------------------------------------------------------------------------------------------- | -------------------- | -------------- |
| Microsoft Entra ID                                                                                                | Ja                   |                |
| Microsoft Entra ID und On-Premises-AD mit AD FS (wird für SSO benötigt)                                           | Ja                   | Ja             |
| Microsoft Entra ID und lokale AD mit DirSync, Azure AD Sync, Azure AD Connect – ohne Passwortsynchronisierung     | Ja                   | Ja             |
| Microsoft Entra ID und On-Premises AD mit DirSync, Azure AD Sync, Azure AD Connect – mit Passwortsynchronisierung | Ja                   |                |
| Lokales Active Directory                                                                                          |                      | Ja             |

Ein Azure-Konto mit der Rolle Global Administrator ist erforderlich, um MFA Server herunterzuladen und zu aktivieren. Die Synchronisierung mit Microsoft Entra ID (über AD Connect) oder einer benutzerdefinierten DNS-Domäne ist nicht erforderlich, um einen MFA Server einzurichten, der ausschließlich vor Ort läuft.

Benutzer müssen in den MFA Server importiert und für die MFA-Authentifizierung konfiguriert werden.

Parallels RAS authentifiziert Benutzer mit MFA Server unter Verwendung des RADIUS Second-Level-Authentifizierungsanbieters. MFA Server muss daher so konfiguriert werden, dass RADIUS-Client-Verbindungen vom RAS-Server aus möglich sind.

Der Authentifizierungsprozess durchläuft die folgenden Schritte:

![Azure\_MFA\_Diagram.png](https://download.parallels.com/ras/v19/docs/de_DE/Parallels-RAS-19-Administrators-Guide/azure_mfa_diagram.png)

In Stufe 2 kann der Benutzer entweder über RADIUS oder Windows AD authentifiziert werden. Eine Aufforderung zur doppelten Eingabe der Zugangsdaten (in Stufe 1 und 6) wird vermieden, indem die Option zur Weiterleitung des Passworts aktiviert wird.

Was this topic helpful?


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.parallels.com/landing/ras-admin-guide/v21-de-de/verbindungs-und-authentifizierungseinstellungen/multifaktor-authentifizierung/verwenden-von-radius/konfigurieren-von-azure-mfa.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
