Publish an application with NTLM authentication

Mountain Pond 1,346 Reputation points
2024-05-10T18:04:38.6366667+00:00

Hello, Azure has an authentication application that is configured to use the NTLM AD provider. This is a virtual machine with IIS and users logged into the domain transparently open the site without authentication.

We would like to protect applications using WAF2, as well as make it secure.

As it turned out, Application Gateway v2 does not support NTLM.

Perhaps Azure has a solution that could solve this. As far as I remember, it was possible to find compromises in TMG UAG.

Thank you.

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
595 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
973 questions
Azure Web Application Firewall
{count} votes

Accepted answer
  1. ChaitanyaNaykodi-MSFT 23,426 Reputation points Microsoft Employee
    2024-05-11T03:40:34.8866667+00:00

    @Mountain Pond

    Thank you for reaching out.

    I understand that you have an Azure virtual machine with IIS configured for NTLM AD provider authentication. This allows domain users to access the site transparently. However, you want to improve security and utilize WAF2 for protection. Unfortunately, you discovered Application Gateway v2 doesn't support NTLM.

    Yes, your understanding here is correct and Application Gateway v2 doesn't support NTLM. The Azure Front Door Service is also not validated to work alongside NTLM authentication and I checked internally can could find that customers have run into issues while using Azure Front Door Service with NTLM auth.

    The recommended solution in this case is to update authentication method instead. It will also help if you could upvote this feedback item for this request on our feedback portal.

    If it helps you can also go through this blog post on how the windows team is reducing dependencies on NTLM.

    Hope this helps! Please let me know if you have any additional questions. Thank you!

    0 comments No comments

0 additional answers

Sort by: Most helpful