AZTCO MFA / Remote access security

Make every sensitive login a deliberate decision.

Protect remote access and Windows environments with device approval, controlled OTP fallback, and an operational view of users, servers, policies, and connector health.

  • RDP
  • RD Gateway
  • RDWeb
  • NPS
  • Windows logon
The client view

A practical security layer for the access your people cannot lose.

AZTCO MFA is built around a simple moment: someone needs access. The platform adds a clear approval step while giving administrators the tools to manage the systems behind that decision.

It brings authentication paths, enrolled devices, synchronized users, servers, policies, and activity records into one tenant-aware control plane.

01Protect key Windows paths

Apply MFA where remote and Windows access starts.

02Give users a clear approval action

Approve on an enrolled device or use a controlled fallback flow.

03Operate with evidence

Keep access, connector, server, and audit visibility close to the team.

01 / Protect

Put a second factor at the point of access.

Access paths

Cover the Windows and remote access routes your organization already uses.

AZTCO MFA supports server-side challenge flows for RDP, RD Gateway, RDWeb, NPS, and Windows logon and unlock through purpose-built Windows connectors.

A

Remote Desktop Services

Add a confirmed second step to RDP, RD Gateway, and RDWeb access scenarios.

B

NPS and RADIUS

Use the NPS extension to continue or reject an authentication request based on the approved MFA challenge.

C

Windows logon & unlock

Use the Credential Provider for a Windows sign-in or unlock approval path, with direct RDP enforcement managed through explicit policy conditions.

02 / Confirm

Make the right approval action available at the right moment.

Device approval

Let people approve access on an enrolled device.

Users enroll a device for the tenant, receive a challenge, and approve it through the web-based authenticator experience. When push is unavailable, a controlled fallback OTP path can be used according to policy.

  1. 01
    Enroll

    Register an approved user device for the organization’s MFA experience.

  2. 02
    Challenge

    The protected connection creates a challenge and waits for the user’s decision.

  3. 03
    Approve or use fallback

    Grant access with device approval, or follow the permitted OTP fallback route when necessary.

03 / Align

Keep the people in the security system aligned with the people in your environment.

Users & policy

Bring your identity source and access rules into the operating model.

Tenant administrators can use the Windows sync agent to bring in Active Directory users from a selected group or search base, or local Windows users when there is no domain.

AD or local-user syncSynchronize user metadata, status, and optional group information without sending directory bind credentials or Windows passwords to the platform.
Server policyApply connector and server policy while retaining deliberate controls for sensitive enforcement settings.
Device managementReview and manage enrolled devices as part of the tenant’s authentication posture.
Licensed tenant accessManage the tenant workspace, users, and authentication capability with license-aware administration.
04 / Deploy

Give operations a repeatable way to bring protected systems online.

Connectors & servers

Register the server. Generate its bundle. Know its state.

The administration workspace keeps server inventory and connector deployment close to policy and operational health, so a rollout has a visible home after installation.

A

Scoped server bundles

Generate connector installation bundles with a server-scoped service key and activation token.

B

Connector choices

Use the appropriate path for Credential Provider, NPS Extension, or AD / local user sync operations.

C

Explicit fail policy

Set connector behavior intentionally for availability scenarios, including a fail-open or fail-closed policy choice.

05 / See

Move from a security setting to a managed service.

Operations & audit

Keep the security team close to the state of remote access.

AZTCO MFA provides the operational views administrators need to follow authentication activity, deployed systems, and connector state over time.

Audit history

Review recorded tenant activity and use export capability when the organization needs a portable audit record.

Connector health

Installed connectors and sync agents report their own health, so administrators can see the deployment state without relying on a separate scheduled probe.

Server inventory

Register and manage servers centrally, with connector type and deployment information in the same control plane.

Service keys & alerts

Manage service credentials and operational alerts through the administrator workspace.

Start with your access path

Make remote access a confident, accountable step.

Start an AZTCO MFA workspace, or talk with us about the Windows, RDS, NPS, and user-sync environment you need to protect.