KeycloakPro

Workforce MFA · Windows Logon MFA

MFA at the Windows sign-in screen and over RDP

Keycloak doesn't run on Windows desktops by itself, so we add the pieces that let it: a credential provider for console and RDP logons, and RADIUS for Remote Desktop Gateway — all enforcing the MFA policy you already run in Keycloak.

  • Console, RDP and RD Gateway
  • One MFA policy in Keycloak
  • Planned offline access

Standards & integrations

  • Windows Credential Provider
  • RADIUS
  • Microsoft NPS
  • RD Gateway
  • TOTP
  • Active Directory

Overview

What it takes to put MFA on Windows

Windows sign-in is controlled by credential providers on each machine, and Remote Desktop Gateway authorises connections through Microsoft NPS. Neither talks to Keycloak on its own. We deploy a credential provider — an open-source option or one built for you — that checks the second factor against Keycloak, point RD Gateway at a RADIUS front end for Keycloak, and decide in advance what happens when a laptop has no network.

What we deliver

  • Logon scenario map and offline policy
  • Credential provider packaged for Intune or Group Policy
  • Highly available RADIUS front end for Keycloak
  • NPS and RD Gateway configuration
  • Pilot and group-based rollout plan
  • Break-glass procedure and support runbook

Capabilities

What Windows Logon MFA covers

Configured, tested and documented on upstream Keycloak — then handed over or operated by us.

  • Credential provider on each host

    A credential provider adds the second-factor step to console and RDP logons on Windows 10, Windows 11 and Windows Server, verified against Keycloak.

  • RD Gateway through NPS

    Remote Desktop Gateway sends connection requests to NPS, which forwards them over RADIUS to Keycloak — MFA for every session without an agent on each server.

  • RADIUS front end for Keycloak

    An open-source Keycloak RADIUS extension or FreeRADIUS integrated with Keycloak turns RADIUS requests into Keycloak authentications.

  • Offline and break-glass policy

    Cached sign-in behaviour, emergency codes and local admin accounts are decided up front instead of discovered during an outage.

  • Rollout by group

    MFA for admins and servers first, then everyone — scoped by Active Directory group so enforcement happens in controlled waves.

  • Sign-ins in one event log

    Windows and RDP authentications land in Keycloak's event log alongside web sign-ins, ready to forward to your SIEM.

Compatibility

Windows sign-in scenarios

Each scenario uses a different enforcement point. We confirm the credential provider and Windows versions during the pilot.

PlatformIntegrationNotes
Windows 10 / 11 console sign-inCredential provider → KeycloakOffline behaviour set explicitly by policy.
Windows Server, direct RDPCredential provider on the target serverCheck Network Level Authentication settings with the provider you use.
Remote Desktop GatewayNPS → RADIUS → KeycloakNo agent on individual servers; raise NPS timeouts for push approvals.
Local admin and break-glass accountsExcluded or emergency codesDocumented, monitored and reviewed.

How it works

From first call to production

  1. Map your logon scenarios

    We list who signs in where — desktops, laptops, servers, RDP, RD Gateway — and agree the MFA and offline rules for each.

  2. Pilot with IT and admins

    The credential provider and RADIUS front end go to IT staff and privileged accounts first, with support procedures tested along the way.

  3. Roll out by group

    Enforcement expands group by group through Intune or Group Policy, with a rollback switch at every stage.

Use cases

Where teams put it to work

  • Privileged server access

    Require MFA for RDP to domain controllers, jump hosts and production servers.

  • Remote and hybrid staff

    Protect laptops that leave the office, with a clear, tested rule for signing in offline.

  • Audit and insurance questionnaires

    Answer questions about MFA for remote access and privileged logons with evidence from Keycloak's event log.

FAQ

Windows Logon MFA questions, answered

Does Keycloak include a Windows credential provider?

No. Keycloak makes the authentication decision; a credential provider on the Windows machine collects the second factor and asks Keycloak to verify it. We select, package and maintain that component.

What happens when a laptop is offline?

Credential providers handle this differently — some allow cached sign-in, some use offline codes. We agree the behaviour with your security team and configure it explicitly.

Can we protect RDP without installing anything on servers?

For connections through Remote Desktop Gateway, yes: MFA happens at the gateway through NPS and RADIUS. Direct RDP to a server needs the credential provider on that server.

Ready to roll out Windows Logon MFA?

Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.

Browse all solutions