4 ms·
But how then does people working from home logon to their AD joined computers? if you cannot expose the AD server to the public internet, can you then actually
by Stranger43 4y ago
But how then does people working from home logon to their AD joined computers?
if you cannot expose the AD server to the public internet, can you then actually use windows in remote first organization?
Those servers have been exposed to the internet because if they weren't the organizations using them would be forced to solve the chicken and egg problem of how to authenticate the users against an authentication server they cannot access without authentication.
- robertlagrant 4y agoYou can use Okta, AAD, etc to front your AD with OAuth2 and secure your VPN with that.
- Dave3of5 4y ago> But how then does people working from home logon to their AD joined computers? I work in this exact type of environment. Your laptop is joined to the domain in office before being sent to you. You can of course logon to the laptop even though it cannot connect to the domain. You just have to connect to the VPN and domain periodically to get gp updates if there is some mandatory software it'll install when you connect. So you connect to the VPN after you logon locally. You also have to connect to the domain to change your password. > Those servers have been exposed to the internet because if they weren't the organizations using them would be forced to solve the chicken and egg problem of how to authenticate the users against an authentication server they cannot access without authentication. No you can logon to a computer with your domain credentials even when it's not connected to the domain.
- jve 4y agoActive Directory Federation Services: https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/deployment/best-practices-securing-ad-fs https://learn.microsoft.com/en-us/windows-server/identity/ad... The internet facing deployment means you have to set up ADFS Web Application Proxy in DMZ that is NOT domain joined and can communicate with domain-joined ADFS service. ADFS allows plenty of stuff, including 2FA, for example for trusted devices only, which has been registered with ADFS and uses certificate based auth. It allows SSO with online services like Azure, Google Workspace and more. Edit: Ahh, sorry, the story is about not logging into web apps, but domain joined computer. Credentials are cached on user laptop, so you can login without network (you can prevent credential caching if you will. You should for domain admin accounts). Or you setup always on VPN (DirectAccess or wireguard) so that you always have the connectivity.