Please consider the request as urgent and critical. As i had raised it with Office 365 community, they have routed me to the Directory services forum.
I am planning to deploy workplace join with DRS in my environment and looking for your valuable feedback.
Current Environment:
DC: Windows Server 2008 R2
Domain & Forest functional level: 2003
ADFS 2.0 & ADFS proxy deployed
2FA by 3rd party app
In order for workplace join, please confirm if my understanding is cporrect
a) Upgrade the domain controller from 2008 to 2012 R2
b) Replace ADFS 2.0 with ADFS 2012 R2
c) Replace ADFS proxy with WAP
d) Upgrade the forest & domain functional level to 2012?
e) Can cert based authentication be used for external users as 2nd Factor Authentication?
f) what are the other 2FA options (not looking for MFA by O365 or Azure. As it uses APPPassword for Non-Browser)
Any pointer will be deeply appreciated.
Regards,
Dematri
Regards, Dematri