You plan to allow users to run internal applications from outside the company’s network.
You have a Windows Server 2012 R2 that has the Active Directory Federation Services (AD FS) role installed.
You must secure on-premises resources by using multi-factor authentication (MFA).
You need to design a solution to enforce different access levels for users with personal Windows 8.1 or iOS 8 devices.
Solution: You install a local instance of the MFA Server. You connect the instance to the Microsoft Azure MFA provider and then you use Microsoft
Intune to manage personal devices.
Does this meet the goal?
A.
Yes
B.
No
Not so sure this is right anymore. Requirements seem to be MFA and Workplace Join as per links provided by Han Solo a few questions from here.
Yes
Windows domain-joined devices. Managed by System Center Configuration Manager (in the current branch) deployed in a hybrid configuration.
Windows 10 Mobile work or personal devices. Managed by Intune or by a supported third-party mobile device management system.
iOS and Android devices. Managed by Intune.
Source: https://docs.microsoft.com/en-us/azure/active-directory/active-directory-conditional-access