I agree if it prompted over and over wouldn't be useful, but When we use MFA/2FA with other applications like Outlook, Skype for Business, or other website resources they don't re-prompt for MFA until a policy timeout period (30 days, etc). To me it seems the world is heading this direction, why not wireless authentication (or at least for a period of policy timeout). Microsoft's RADIUS Network Policy server supports RADIUS with MFA, SourceURL:https://docs.microsoft.com/en-us/azure/multi-factor-authentication/nps-extension-vpn VPN integration with Azure MFA using NPS extension | Microsoft Docs The VPN server receives an authentication request from a VPN user that includes the username and password to connect to a resource, such as a Remote Desktop session. Acting as a RADIUS client, VPN server converts the request to a RADIUS Access-Request message and sends the message (password is encrypted) to the RADIUS (NPS) server where the NPS extension is installed. The username and password combination is verified in Active Directory. If the username / password is incorrect, the RADIUS Server sends an Access-Reject message. If all conditions as specified in the NPS Connection Request and Network Policies are met (for example, time of day or group membership restrictions), the NPS extension triggers a request for secondary authentication with Azure MFA. Azure MFA communicates with Azure Active Directory, retrieves the users's details, and performs the secondary authentication using the method configured by the user (text message, mobile app, and so on). (I assume this secondary authentication could be configured, as to when and what rules it should ask) Upon success of the MFA challenge, Azure MFA communicates the result to the NPS extension. After the connection attempt is both authenticated and authorized, the NPS server where the extension is installed sends a RADIUS Access-Accept message to the VPN server (RADIUS client). The user is granted access to the virtual port on VPN server and establishes an encrypted VPN tunnel.
... View more