Skip to main content
Grey Grin
Visitor III
July 15, 2026
Solved

Adding MFA to OpenVPN users authenticated through Active Directory

  • July 15, 2026
  • 4 replies
  • 73 views

Hi,

We're reviewing our VPN authentication setup and would like to add MFA for remote users.

At the moment, OpenVPN authenticates users against our on-premises Active Directory. Because some parts of our environment don't have reliable Internet access, we're trying to avoid cloud-based MFA platforms.

I'd be interested to hear how others have approached this.

  • Did you integrate MFA through RADIUS, LDAP, or another method?
  • Which solution has been the most reliable in production?
  • Any issues with OpenVPN authentication or user experience after enabling MFA?
  • Anything you'd recommend before rolling it out?

Thanks in advance for sharing your experience.

Best answer by Ethan Brooks

We had a similar requirement and ended up keeping Active Directory as the identity source while adding MFA through RADIUS.

After testing a couple of products, we chose Protectimus because we needed an on-premises deployment instead of a cloud-only service. The integration with OpenVPN was straightforward, and we haven't had any stability issues since rolling it out.

One thing I'd recommend is validating your RADIUS timeout values and recovery workflow before enabling MFA for all users. That saved us a few headaches during deployment.

4 replies

henry-collins
Visitor III
July 15, 2026

If you want to keep everything on-prem, RADIUS is usually the cleanest option. We've had good results with on-prem MFA servers that integrate with Active Directory and present themselves as a RADIUS backend for OpenVPN. Before rolling it out, test your offline and recovery scenarios carefully, those tend to cause more trouble than the MFA integration itself.

Full-Stack Developer | SEO Strategist | Helping users with software & troubleshooting solutions.
Grey Grin
Grey GrinAuthor
Visitor III
July 16, 2026

Thanks for sharing your experience!

That's a good point about testing the offline and recovery scenarios. Those are easy to overlook during deployment but can become a real issue later. We'll definitely include that in our testing before rolling anything out.

Visitor III
July 16, 2026

We had a similar requirement and ended up keeping Active Directory as the identity source while adding MFA through RADIUS.

After testing a couple of products, we chose Protectimus because we needed an on-premises deployment instead of a cloud-only service. The integration with OpenVPN was straightforward, and we haven't had any stability issues since rolling it out.

One thing I'd recommend is validating your RADIUS timeout values and recovery workflow before enabling MFA for all users. That saved us a few headaches during deployment.

New Member
July 16, 2026

I still don't understand why it's impossible to add a field to the MFA similar to sAMAccountName but for email or phone. So Fortigate can send mails or SMS directly. Hope in next release

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!