Adding MFA to OpenVPN users authenticated through Active Directory
Hi,
We're reviewing our VPN authentication setup and would like to add MFA for remote users.
At the moment, OpenVPN authenticates users against our on-premises Active Directory. Because some parts of our environment don't have reliable Internet access, we're trying to avoid cloud-based MFA platforms.
I'd be interested to hear how others have approached this.
- Did you integrate MFA through RADIUS, LDAP, or another method?
- Which solution has been the most reliable in production?
- Any issues with OpenVPN authentication or user experience after enabling MFA?
- Anything you'd recommend before rolling it out?
Thanks in advance for sharing your experience.
