Multi-CloudHow-To & HardeningRetrospectives

How to Enforce MFA on Every Remote Access Portal

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from February 2024, written in 2026 with the benefit of hindsight.

Change Healthcare and Colonial Pipeline were both breached through remote access without MFA. Here is how to enforce MFA on every remote access portal.

Step 1: Inventory every remote access entry point

  • VPNs and SSL VPN portals.
  • Citrix, VMware Horizon and other virtual desktop gateways.
  • RD Gateways and RDP exposed directly.
  • Remote support tools (ScreenConnect, TeamViewer, BeyondTrust and others).
  • Admin interfaces of network devices and appliances.
  • SaaS admin consoles.

Confirm with external scanning, firewall NAT rules and acquisition records.

Step 2: Integrate with Entra ID

Prefer authentication through Entra ID so Conditional Access applies:

  • SAML/OIDC SSO for modern gateways (Citrix, many VPNs, SaaS).
  • NPS extension for Microsoft Entra multifactor authentication for RADIUS-based VPNs and RD Gateways.
  • Entra application proxy or Entra Private Access to publish internal apps without a VPN.

Step 3: Apply Conditional Access

Require MFA (ideally phishing-resistant) and compliant devices for remote access apps.

Step 4: Remove local accounts

Disable local and LDAP-only accounts on gateways, except a documented break-glass account protected separately.

Step 5: Verify continuously

  • Monthly external scans for new remote access endpoints.
  • Sign-in log review for single-factor access to remote access apps.
  • Include remote access MFA in acquisition integration checklists.

Step 6: Plan for edge vulnerabilities

Remote access appliances are frequently exploited. Patch on an emergency timeline and subscribe to vendor advisories.

enforce mfa remote access portalsChange Healthcare2024

More on this story