Loading...

One step closer to modernization: The MFA Server Migration Utility

One step closer to modernization: The MFA Server Migration Utility

Hi folks! 

 

We are always working to keep maximize your security and productivity. We focus on solutions to make modernization as easy as possible. As customers work towards modernizing security by adopting Azure AD, they have told us they need help migrating from on-premises MFA Server to cloud-based Azure MFA. This gets them a bunch of simplification – they can retire their on-premises MFA Server *and* the ADFS deployment needed to support it. Today, I am excited to announce the availability of the new Azure MFA Server Migration Utility, which we hope will make your modernization journey much easier!

 

Since July of 2019, we have blocked new downloads of the on-premises MFA Server, reflecting the fact the Azure MFA is our premier MFA experience, offering lower TCO, simpler deployment, better security, and many more features than the MFA Server. The Azure MFA Server Migration Utility makes it easy for admins to take advantage of these advances and modernize their infrastructure by migrating their users from on-premises Azure MFA Server to Azure MFA.

 

There are two pieces to this tool:

  • The Azure MFA Server Migration Utility facilitates the migration of user authentication data stored on-premises, directly into Azure AD, all without requiring any re-registration or action from their end-users.  It is included in the latest update of Azure MFA Server.
  • Staged Rollout for Azure MFA functionality within Azure AD, allowing admins to selectively test and move users to Azure MFA without requiring any changes to federation settings.

 

Getting started 

 

Step 1: Upgrade your primary Azure MFA Server

 

Install the latest Azure MFA Server update on your primary Azure MFA Server. If the remaining machines in your MFA Server deployment are running on version 6.1.0 or higher, no other servers need to be upgraded.

 

Step 2: Target users for migration

 

Once installed, open the new Migration Utility.

 

Trevor_Rusher_3-1661968809751.png

 

Migrating user data is as easy as selecting the Azure AD group containing users (or nested groups of users) you wish to migrate, defining the various registered MFA methods that should be moved to Azure AD, and then clicking “Migrate Users”.

 

Step 3: Target users for Azure MFA

 

Once user data has been migrated, use Staged Rollout for Azure MFA to ease migrations by determining which users should use Azure MFA, based on targeted group membership:

 

Trevor_Rusher_2-1661968484984.png

 

Since no changes to your tenant or federation settings are required, carrying out testing is extremely low-risk and can be done with as many or as few users as you wish.

 

Once testing and migrations have been completed, you can quickly and easily retire your entire MFA Server deployment, instantly reducing infrastructure and maintenance costs, while boosting the availability and reliability of your MFA Service. Head on over to the MFA Server Migration documentation page to get started!

 

As always, we’re excited to get your feedback and learn from you!

 

-Alex Weinert, Director of Identity Security (Twitter:@alex_t_weinert)

 

Learn more about Microsoft identity:

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.