Securing devo server for public internet access

Securing devo server for public internet access

avatar

1) How do we secure open Devolutions Server to the public internet access. We would like to get the product working off of our VPN. To that end...
2) How do we deploy and configure the gateway component? Is there a KB on this or assistance we may recieve?
and lastly,
3) would this https://docs.devolutions.net/kb/devolutions-server/how-to-articles/azure-portal-configuration-guide-microsoft-authentication/
allow for us to circumvent question 1 and just use our Microsoft authenticator app to get into devo?

All Comments (3)

avatar

Hello,

For your first question, you can refer to the following topics, but please keep in mind the warning in the first link:


For the second question, you can refer to https://docs.devolutions.net/server/dgw/server-configuration/

For the last question, by using Microsoft / AAD authentication, the authentication will occur on the Microsoft side, including your MFA. However, if you want your Devolutions Server to be available online, you will still need to secure your Devolutions Server instance.

Best regards,

Richard Boisvert

avatar

Thanks Richard, what is the best way to implement AAD/MS auth as the default auth method? Currently we have users added via LDAP using a local domain account. Is it 100% necessary to add the users through linking devolutions server and our azure instance together?

avatar

Hello Ross,

You must authenticate using Microsoft/AAD authentication instead of domain authentication. You can follow this KB to configure it - https://docs.devolutions.net/kb/devolutions-server/how-to-articles/azure-portal-configuration-guide-microsoft-authentication/

Once done, you can migrate your current domain users to Microsoft in Devolutions Server - https://docs.devolutions.net/kb/devolutions-server/how-to-articles/authentication-migration/ . This way, they will keep their user vault and their user-specific settings.

Best regards,

Richard Boisvert