Advanced Authentication can be configured as an IDP for Azure AD. However, it is necessary AA connects to Active Directory in order to register the user and enrol necessary authentication methods, not to mention key data to provide to Azure AD like ImmutableID.

Some organisations have several Active Directories synchronised to Azure AD, which makes configuring Active Directory as repository much more cumbersome that necessary. Azure AD LDAP interface is not always present either. Some Azure AD users can also be cloud native and not be present in Active Directory.

For all those reasons, we should be able to use Azure AD as a user repository and provide seamless MFA to Azure AD and its apps.

Comments

  • We will investigate this request.