Do you use MFA for Active Directory logons?

๐Ÿ”’ Secure Bits ๐Ÿ’ก

๐——๐—ผ ๐˜†๐—ผ๐˜‚ ๐˜‚๐˜€๐—ฒ ๐— ๐—™๐—” ๐—ณ๐—ผ๐—ฟ ๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐—น๐—ผ๐—ด๐—ผ๐—ป๐˜€?

If you follow CIS/NIST (or regulations like NIS2), you already know the direction: password-only authentication is ๐—ป๐—ผ ๐—น๐—ผ๐—ป๐—ด๐—ฒ๐—ฟ ๐—ฒ๐—ป๐—ผ๐˜‚๐—ด๐—ต.

The hard part is implementation.

In classicย ๐—ช๐—ถ๐—ป๐—ฑ๐—ผ๐˜„๐˜€ + ๐—”๐—— ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜๐˜€, truly native options are limited:

๐Ÿ”น Windows Hello for Business can work well – but in many setups it ends up mainly as a user solution (often hybrid).

๐Ÿ”น Smart cards / PKI can cover much more – but deploying PKI properly (and managing certificate lifecycle) is a project on its own.

Thatโ€™s why I started collaborating with Systola and their solution SystoLock – built for the โ€œ๐—ถ๐—ป-๐—ฏ๐—ฒ๐˜๐˜„๐—ฒ๐—ฒ๐—ปโ€ reality:

โžก๏ธ you want MFA/passwordless for Windows and AD, but you donโ€™t want a full PKI rollout (it is also more budget friendly…).

๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—ถ๐˜ ๐—ฐ๐—ฎ๐—ป ๐—ฏ๐—ฒ ๐—ถ๐—ป๐˜๐—ฒ๐—ด๐—ฟ๐—ฎ๐˜๐—ฒ๐—ฑ:

๐Ÿ”น Windows domain logon (interactive + RDP + UAC/impersonation)

๐Ÿ”น RD Gateway / RDP farms (single-step, no MFA โ€œdouble promptsโ€)

๐Ÿ”น SaaS / cloud via SAML 2.0 / AD FS (M365, Salesforce, etc.)

๐Ÿ”น Entra ID federation with local passwordless identities

๐Ÿงช ๐—ช๐—ฎ๐—ป๐˜ ๐˜๐—ผ ๐˜๐—ฟ๐˜† ๐—ถ๐˜?

Link in comments. Hereโ€™s how it works:

1. Open the page โ†’ youโ€™ll see the license options (one is free).

2. Click Request demo.

3. Systola will create your eval account and send access so you can install and test.

If you give it a spin, ๐˜๐—ฒ๐—น๐—น ๐—บ๐—ฒ ๐—ต๐—ผ๐˜„ ๐—ถ๐˜ ๐—ด๐—ผ๐—ฒ๐˜€ – I can help and may be able to arrange a discount for paid tiers.

๐Ÿ’ฌ What MFA approach are you using for AD today – WHfB, PKI/smart cards, something else, or nothing yet?