Workforce MFA · Windows Logon MFA
MFA at the Windows sign-in screen and over RDP
Keycloak doesn't run on Windows desktops by itself, so we add the pieces that let it: a credential provider for console and RDP logons, and RADIUS for Remote Desktop Gateway — all enforcing the MFA policy you already run in Keycloak.
- Console, RDP and RD Gateway
- One MFA policy in Keycloak
- Planned offline access
Standards & integrations
- Windows Credential Provider
- RADIUS
- Microsoft NPS
- RD Gateway
- TOTP
- Active Directory
Overview
What it takes to put MFA on Windows
Windows sign-in is controlled by credential providers on each machine, and Remote Desktop Gateway authorises connections through Microsoft NPS. Neither talks to Keycloak on its own. We deploy a credential provider — an open-source option or one built for you — that checks the second factor against Keycloak, point RD Gateway at a RADIUS front end for Keycloak, and decide in advance what happens when a laptop has no network.
What we deliver
- Logon scenario map and offline policy
- Credential provider packaged for Intune or Group Policy
- Highly available RADIUS front end for Keycloak
- NPS and RD Gateway configuration
- Pilot and group-based rollout plan
- Break-glass procedure and support runbook
Capabilities
What Windows Logon MFA covers
Configured, tested and documented on upstream Keycloak — then handed over or operated by us.
Credential provider on each host
A credential provider adds the second-factor step to console and RDP logons on Windows 10, Windows 11 and Windows Server, verified against Keycloak.
RD Gateway through NPS
Remote Desktop Gateway sends connection requests to NPS, which forwards them over RADIUS to Keycloak — MFA for every session without an agent on each server.
RADIUS front end for Keycloak
An open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak turns RADIUS requests into Keycloak authentications.
Offline and break-glass policy
Cached sign-in behaviour, emergency codes and local admin accounts are decided up front instead of discovered during an outage.
Rollout by group
MFA for admins and servers first, then everyone — scoped by Active Directory group so enforcement happens in controlled waves.
Sign-ins in one event log
Windows and RDP authentications land in Keycloak's event log alongside web sign-ins, ready to forward to your SIEM.
Compatibility
Windows sign-in scenarios
Each scenario uses a different enforcement point. We confirm the credential provider and Windows versions during the pilot.
| Platform | Integration | Notes |
|---|---|---|
| Windows 10 / 11 console sign-in | Credential provider → Keycloak | Offline behaviour set explicitly by policy. |
| Windows Server, direct RDP | Credential provider on the target server | Check Network Level Authentication settings with the provider you use. |
| Remote Desktop Gateway | NPS → RADIUS → Keycloak | No agent on individual servers; raise NPS timeouts for push approvals. |
| Local admin and break-glass accounts | Excluded or emergency codes | Documented, monitored and reviewed. |
How it works
From first call to production
Map your logon scenarios
We list who signs in where — desktops, laptops, servers, RDP, RD Gateway — and agree the MFA and offline rules for each.
Pilot with IT and admins
The credential provider and RADIUS front end go to IT staff and privileged accounts first, with support procedures tested along the way.
Roll out by group
Enforcement expands group by group through Intune or Group Policy, with a rollback switch at every stage.
Use cases
Where teams put it to work
Privileged server access
Require MFA for RDP to domain controllers, jump hosts and production servers.
Remote and hybrid staff
Protect laptops that leave the office, with a clear, tested rule for signing in offline.
Audit and insurance questionnaires
Answer questions about MFA for remote access and privileged logons with evidence from Keycloak's event log.
FAQ
Windows Logon MFA questions, answered
Does Keycloak include a Windows credential provider?
No. Keycloak makes the authentication decision; a credential provider on the Windows machine collects the second factor and asks Keycloak to verify it. We select, package and maintain that component.
What happens when a laptop is offline?
Credential providers handle this differently — some allow cached sign-in, some use offline codes. We agree the behaviour with your security team and configure it explicitly.
Can we protect RDP without installing anything on servers?
For connections through Remote Desktop Gateway, yes: MFA happens at the gateway through NPS and RADIUS. Direct RDP to a server needs the credential provider on that server.
Ready to roll out Windows Logon MFA?
Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.