Remote Desktop Services
Add a confirmed second step to RDP, RD Gateway, and RDWeb access scenarios.
Protect remote access and Windows environments with device approval, controlled OTP fallback, and an operational view of users, servers, policies, and connector health.
AZTCO MFA is built around a simple moment: someone needs access. The platform adds a clear approval step while giving administrators the tools to manage the systems behind that decision.
It brings authentication paths, enrolled devices, synchronized users, servers, policies, and activity records into one tenant-aware control plane.
Apply MFA where remote and Windows access starts.
Approve on an enrolled device or use a controlled fallback flow.
Keep access, connector, server, and audit visibility close to the team.
Put a second factor at the point of access.
AZTCO MFA supports server-side challenge flows for RDP, RD Gateway, RDWeb, NPS, and Windows logon and unlock through purpose-built Windows connectors.
Add a confirmed second step to RDP, RD Gateway, and RDWeb access scenarios.
Use the NPS extension to continue or reject an authentication request based on the approved MFA challenge.
Use the Credential Provider for a Windows sign-in or unlock approval path, with direct RDP enforcement managed through explicit policy conditions.
Make the right approval action available at the right moment.
Users enroll a device for the tenant, receive a challenge, and approve it through the web-based authenticator experience. When push is unavailable, a controlled fallback OTP path can be used according to policy.
Register an approved user device for the organization’s MFA experience.
The protected connection creates a challenge and waits for the user’s decision.
Grant access with device approval, or follow the permitted OTP fallback route when necessary.
Keep the people in the security system aligned with the people in your environment.
Tenant administrators can use the Windows sync agent to bring in Active Directory users from a selected group or search base, or local Windows users when there is no domain.
Give operations a repeatable way to bring protected systems online.
The administration workspace keeps server inventory and connector deployment close to policy and operational health, so a rollout has a visible home after installation.
Generate connector installation bundles with a server-scoped service key and activation token.
Use the appropriate path for Credential Provider, NPS Extension, or AD / local user sync operations.
Set connector behavior intentionally for availability scenarios, including a fail-open or fail-closed policy choice.
Move from a security setting to a managed service.
AZTCO MFA provides the operational views administrators need to follow authentication activity, deployed systems, and connector state over time.
Review recorded tenant activity and use export capability when the organization needs a portable audit record.
Installed connectors and sync agents report their own health, so administrators can see the deployment state without relying on a separate scheduled probe.
Register and manage servers centrally, with connector type and deployment information in the same control plane.
Manage service credentials and operational alerts through the administrator workspace.
Start an AZTCO MFA workspace, or talk with us about the Windows, RDS, NPS, and user-sync environment you need to protect.