{"id":18546,"date":"2026-05-18T09:47:45","date_gmt":"2026-05-18T09:47:45","guid":{"rendered":"https:\/\/www.protectimus.com\/es-mfa-for-active-directory\/"},"modified":"2026-08-27T19:08:18","modified_gmt":"2026-08-27T19:08:18","slug":"mfa-for-active-directory","status":"publish","type":"page","link":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/","title":{"rendered":"MFA para Active Directory: proteja su AD con DSPA"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-page\" data-elementor-id=\"18546\" class=\"elementor elementor-18546 elementor-16711\" data-elementor-post-type=\"page\">\n\t\t\t\t<div class=\"elementor-element elementor-element-223acb9 padded e-flex e-con-boxed e-con e-parent\" data-id=\"223acb9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e4740cc elementor-widget elementor-widget-heading\" data-id=\"e4740cc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">MFA para Active Directory: gu\u00eda completa para proteger su entorno AD<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-045bb52 e-con-full e-flex e-con e-child\" data-id=\"045bb52\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-b4a66c0 e-con-full e-flex e-con e-child\" data-id=\"b4a66c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d41dfc9 elementor-widget elementor-widget-text-editor\" data-id=\"d41dfc9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Active Directory es la base de la gesti\u00f3n de identidades en m\u00e1s del 90% de las empresas Fortune 1000, y tambi\u00e9n uno de los sistemas m\u00e1s atacados en el panorama actual de ciberseguridad. Una cuenta de AD comprometida da al atacante acceso a todo: servidores de archivos, correo electr\u00f3nico, VPN, servicios en la nube y aplicaciones internas. Las contrase\u00f1as por s\u00ed solas ya no bastan. La autenticaci\u00f3n multifactor (MFA) para Active Directory a\u00f1ade una segunda capa de verificaci\u00f3n cr\u00edtica que detiene los ataques basados en credenciales incluso cuando la contrase\u00f1a ya ha sido robada.   <\/span><\/p><p data-start=\"102\" data-end=\"282\"><b>Respuesta r\u00e1pida: <\/b><span style=\"font-weight: 400;\">la MFA para Active Directory exige que el usuario verifique su identidad con un segundo factor \u2014normalmente una contrase\u00f1a de un solo uso (OTP)\u2014 adem\u00e1s de su contrase\u00f1a habitual. Protectimus implementa esto mediante su componente <a href=\"https:\/\/www.protectimus.com\/es\/dspa\/\" target=\"_blank\" rel=\"noopener\">DSPA (Dynamic Strong Password Authentication)<\/a>, que se integra directamente con AD y aplica autom\u00e1ticamente la MFA en todos los servicios conectados \u2014Winlogon, RDP, OWA, ADFS\u2014 sin instalar agentes en cada endpoint. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b35c05a elementor-widget elementor-widget-html\" data-id=\"b35c05a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"BreadcrumbList\",\r\n  \"itemListElement\": [\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 1,\r\n      \"name\": \"Home\",\r\n      \"item\": \"https:\/\/www.protectimus.com\/\"\r\n    },\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 2,\r\n      \"name\": \"Solutions\",\r\n      \"item\": \"https:\/\/www.protectimus.com\/solutions\/\"\r\n    },\r\n    {\r\n      \"@type\": \"ListItem\",\r\n      \"position\": 3,\r\n      \"name\": \"MFA for Active Directory\",\r\n      \"item\": \"https:\/\/www.protectimus.com\/mfa-for-active-directory\/\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7332fbc e-con-full e-flex e-con e-child\" data-id=\"7332fbc\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4b0f868 elementor-widget elementor-widget-heading\" data-id=\"4b0f868\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">\u00cdndice\n<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b78b60 elementor-widget elementor-widget-text-editor\" data-id=\"4b78b60\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#whyactive\"><span style=\"font-weight: 400;\">Por qu\u00e9 Active Directory necesita MFA en 2026<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#howmfaactivedir\"><span style=\"font-weight: 400;\">C\u00f3mo funciona la MFA para Active Directory<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#protectimusdspa\"><span style=\"font-weight: 400;\">Protectimus DSPA: el enfoque \u00fanico para MFA en AD<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#supportedmfa\"><span style=\"font-weight: 400;\">M\u00e9todos de MFA compatibles con Active Directory<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#protectedautomat\"><span style=\"font-weight: 400;\">Qu\u00e9 servicios quedan protegidos autom\u00e1ticamente<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#activemfaforadfs\"><span style=\"font-weight: 400;\">MFA para Active Directory mediante ADFS<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#deployoptions\"><span style=\"font-weight: 400;\">Opciones de implementaci\u00f3n: nube frente a on-premise<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#multidomain\"><span style=\"font-weight: 400;\">Entornos multidominio y de gran empresa<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#howtosetup\"><span style=\"font-weight: 400;\">C\u00f3mo configurar la MFA para Active Directory con Protectimus<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#faq\"><span style=\"font-weight: 400;\">Preguntas frecuentes<\/span><\/a><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"#conclusion\"><span style=\"font-weight: 400;\">Conclusi\u00f3n: proteger Active Directory con MFA en 2026<\/span><\/a><\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cdef92e padded e-flex e-con-boxed e-con e-parent\" data-id=\"cdef92e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56c84d1 elementor-widget elementor-widget-heading\" data-id=\"56c84d1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Datos clave\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bff780b elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"bff780b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d391a8f e-grid e-con-boxed e-con e-child\" data-id=\"d391a8f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-64a96a2 border-left e-flex e-con-boxed e-con e-child\" data-id=\"64a96a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4dfef98 elementor-widget elementor-widget-heading\" data-id=\"4dfef98\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">99,9% de los ataques bloqueados con MFA<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0cc1bea elementor-widget elementor-widget-heading\" data-id=\"0cc1bea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Microsoft<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f5e29e2 elementor-widget elementor-widget-text-editor\" data-id=\"f5e29e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Seg\u00fan Microsoft, m\u00e1s del 99,9% de los ataques de compromiso de cuentas pueden bloquearse con MFA.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f5947b8 border-left e-flex e-con-boxed e-con e-child\" data-id=\"f5947b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fa74c1f elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"fa74c1f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-47e43b7 elementor-widget elementor-widget-heading\" data-id=\"47e43b7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">$4,4 millones de coste medio por brecha en 2026<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-fb629a4 elementor-widget elementor-widget-heading\" data-id=\"fb629a4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">IBM <\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8085769 elementor-widget elementor-widget-text-editor\" data-id=\"8085769\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">El coste medio de una brecha de datos en 2026 alcanz\u00f3 aproximadamente los $4,4 millones (IBM Cost of a Data Breach Report 2026).<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c6c866e elementor-hidden-desktop elementor-hidden-tablet elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"c6c866e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5c0d1fa border-left e-flex e-con-boxed e-con e-child\" data-id=\"5c0d1fa\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d45db87 elementor-widget elementor-widget-heading\" data-id=\"d45db87\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">60% de las brechas involucran credenciales<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-344d455 elementor-widget elementor-widget-heading\" data-id=\"344d455\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Verizon<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3a4d317 elementor-widget elementor-widget-text-editor\" data-id=\"3a4d317\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">El 60% de las brechas involucran el factor humano, principalmente el abuso de credenciales y el phishing (Verizon 2026 DBIR).<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-0ae1e9a padded e-flex e-con-boxed e-con e-parent\" data-id=\"0ae1e9a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e899921 elementor-widget elementor-widget-heading\" data-id=\"e899921\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Ventajas clave<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-86d1b8b elementor-widget elementor-widget-spacer\" data-id=\"86d1b8b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d5e935 e-grid e-con-full e-con e-child\" data-id=\"9d5e935\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-12e9470 e-con-full e-flex e-con e-child\" data-id=\"12e9470\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8644d62 elementor-widget elementor-widget-image\" data-id=\"8644d62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-shield.svg\" class=\"attachment-full size-full wp-image-521\" alt=\"On-Prem MFA Platform icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-317cba7 elementor-widget elementor-widget-heading\" data-id=\"317cba7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Una sola integraci\u00f3n, cobertura total<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d96a026 elementor-widget elementor-widget-text-editor\" data-id=\"d96a026\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>DSPA protege Active Directory a nivel de directorio, no de endpoint. Una \u00fanica integraci\u00f3n protege autom\u00e1ticamente Winlogon, RDP, OWA, ADFS y LDAP al mismo tiempo. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-68b5ae8 e-con-full e-flex e-con e-child\" data-id=\"68b5ae8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8b57400 elementor-widget elementor-widget-image\" data-id=\"8b57400\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"56\" height=\"40\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/03\/icon-cloud-56.svg\" class=\"attachment-full size-full wp-image-17287\" alt=\"Cloud-Based MFA Service icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-767e2aa elementor-widget elementor-widget-heading\" data-id=\"767e2aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Sin software en los equipos de los usuarios<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d73153e elementor-widget elementor-widget-text-editor\" data-id=\"d73153e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>No se requieren agentes en el cliente. DSPA es la \u00fanica soluci\u00f3n MFA agentless para Active Directory que cubre todos los servicios conectados a AD sin tocar los endpoints de los usuarios. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9d3b5b8 e-con-full e-flex e-con e-child\" data-id=\"9d3b5b8\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89d54f8 elementor-widget elementor-widget-image\" data-id=\"89d54f8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"57\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2026\/05\/plat_new.svg\" class=\"attachment-full size-full wp-image-16519\" alt=\"On-premise MFA platform icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f7f585d elementor-widget elementor-widget-heading\" data-id=\"f7f585d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">On-premise o nube privada<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aff0db8 elementor-widget elementor-widget-text-editor\" data-id=\"aff0db8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Se implementa en infraestructura local o en la nube privada, garantizando soberan\u00eda total de los datos, soporte de redes aisladas y cumplimiento normativo.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9ddacc7 e-con-full e-flex e-con e-child\" data-id=\"9ddacc7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-82d1654 elementor-widget elementor-widget-image\" data-id=\"82d1654\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-check.svg\" class=\"attachment-full size-full wp-image-637\" alt=\"Customer Stories section icon \u2013 real-life client experiences\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-eb78c60 elementor-widget elementor-widget-heading\" data-id=\"eb78c60\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Lista para auditor\u00edas desde el primer d\u00eda<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ee318b2 elementor-widget elementor-widget-text-editor\" data-id=\"ee318b2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Soluci\u00f3n certificada OATH y alineada con PCI DSS v4.0, HIPAA, NIST SP 800-63B, SOC 2 e ISO 27001<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cb9fab9 e-con-full e-flex e-con e-child\" data-id=\"cb9fab9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1b3c387 elementor-widget elementor-widget-image\" data-id=\"1b3c387\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"64\" height=\"64\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/clock.svg\" class=\"attachment-full size-full wp-image-17825\" alt=\"Time-Controlled Resource Access feature icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-84c6048 elementor-widget elementor-widget-heading\" data-id=\"84c6048\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Implementaci\u00f3n r\u00e1pida<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1abcc56 elementor-widget elementor-widget-text-editor\" data-id=\"1abcc56\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>El despliegue t\u00edpico de extremo a extremo toma entre 1 y 2 d\u00edas, desde la configuraci\u00f3n de la plataforma hasta la MFA en toda la organizaci\u00f3n para todos los servicios de AD.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7c15682 e-con-full e-flex e-con e-child\" data-id=\"7c15682\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffb514c elementor-widget elementor-widget-image\" data-id=\"ffb514c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"56\" height=\"56\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-srv.svg\" class=\"attachment-full size-full wp-image-624\" alt=\"Protectimus VDI Clients MFA integration icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3382fca elementor-widget elementor-widget-heading\" data-id=\"3382fca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Escalabilidad sin l\u00edmites<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-785b26a elementor-widget elementor-widget-text-editor\" data-id=\"785b26a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Soporta bosques multidominio, clustering, pol\u00edticas de MFA por grupo y despliegues de alta disponibilidad con failover autom\u00e1tico.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-30a9584 elementor-widget elementor-widget-spacer\" data-id=\"30a9584\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-5b50e5c padded e-flex e-con-boxed e-con e-parent\" data-id=\"5b50e5c\" data-element_type=\"container\" data-e-type=\"container\" id=\"whyactive\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-28b1e56 e-con-full e-flex e-con e-child\" data-id=\"28b1e56\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-a6f90e4 elementor-widget elementor-widget-heading\" data-id=\"a6f90e4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Por qu\u00e9 Active Directory necesita MFA en 2026<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9d2498b elementor-widget elementor-widget-text-editor\" data-id=\"9d2498b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Active Directory es el objetivo m\u00e1s valioso en cualquier red corporativa, y protegerlo solo con contrase\u00f1as lo deja cr\u00edticamente expuesto. Implementar autenticaci\u00f3n de dos factores para Active Directory ya no es opcional para ninguna organizaci\u00f3n que maneje datos sensibles. <\/span><\/p><p><span style=\"font-weight: 400;\">Active Directory almacena credenciales de usuario, pol\u00edticas de grupo, permisos de acceso y datos de autenticaci\u00f3n de cada sistema de la organizaci\u00f3n. Cuando un atacante obtiene acceso a una sola cuenta AD con privilegios, puede moverse lateralmente por toda la infraestructura, escalar privilegios, exfiltrar datos e implantar ransomware, todo ello usando credenciales leg\u00edtimas que eluden la mayor\u00eda de los controles de seguridad. <\/span><\/p><p><span style=\"font-weight: 400;\">La magnitud del problema est\u00e1 bien documentada:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>El 60% de las brechas involucran el factor humano<\/b><span style=\"font-weight: 400;\">, y las credenciales robadas siguen siendo el principal vector de acceso inicial, seg\u00fan el Verizon 2026 Data Breach Investigations Report<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Los ataques pass-the-hash y pass-the-ticket<\/b> atacan espec\u00edficamente los tokens de autenticaci\u00f3n de Active Directory, permitiendo al atacante autenticarse sin conocer la contrase\u00f1a real<\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>El Kerberoasting<\/b><span style=\"font-weight: 400;\">, t\u00e9cnica dirigida a cuentas de servicio de AD, sigue creciendo a\u00f1o tras a\u00f1o, seg\u00fan el CrowdStrike 2026 Global Threat Report<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Los ataques de fuerza bruta contra RDP y Winlogon<\/b><span style=\"font-weight: 400;\">, ambos autenticados mediante AD, representan una parte significativa del acceso inicial en incidentes de ransomware<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Los ataques DCSync y Golden Ticket<\/b> <span style=\"font-weight: 400;\">permiten a un adversario que ha llegado a un controlador de dominio extraer o falsificar material de autenticaci\u00f3n, riesgos que las contrase\u00f1as est\u00e1ticas de AD por s\u00ed solas no pueden mitigar<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">El problema tiene una ra\u00edz arquitect\u00f3nica: AD se dise\u00f1\u00f3 en una \u00e9poca en la que el per\u00edmetro corporativo estaba claramente definido. Hoy, con el trabajo remoto, los servicios en la nube y el acceso de contratistas, ese per\u00edmetro pr\u00e1cticamente ha desaparecido. Las credenciales pueden robarse mediante phishing, malware, filtraciones de terceros o averiguarse por fuerza bruta.  <\/span><\/p><p><span style=\"font-weight: 400;\">La <a href=\"https:\/\/www.protectimus.com\/es\/solutions\/\" target=\"_blank\" rel=\"noopener\">autenticaci\u00f3n multifactor<\/a> reduce sustancialmente el riesgo de credenciales robadas al exigir un segundo factor que el atacante no puede obtener de forma remota. Aunque la contrase\u00f1a quede comprometida, la cuenta permanece inaccesible sin acceso a la aplicaci\u00f3n autenticadora del usuario o a otro segundo factor.<br\/> <\/span><\/p><p><span style=\"font-weight: 400;\">Hist\u00f3ricamente, el reto ha sido implementar 2FA para AD en todo el entorno sin interrumpir los flujos de trabajo existentes ni requerir cambios masivos de infraestructura. Ese es exactamente el problema que Protectimus DSPA fue dise\u00f1ado para resolver. <\/span><\/p><p>Como ejemplo real, vea <a href=\"https:\/\/www.protectimus.com\/es\/blog\/customer-stories-dxc-technology-2fa\/\" target=\"_blank\" rel=\"noopener\">c\u00f3mo DXC Technology implement\u00f3 Protectimus DSPA en todos sus servicios conectados a AD.<\/a><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d57877c padded e-flex e-con-boxed e-con e-parent\" data-id=\"d57877c\" data-element_type=\"container\" data-e-type=\"container\" id=\"howmfaactivedir\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1698709 e-con-full e-flex e-con e-child\" data-id=\"1698709\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-88c2197 elementor-widget elementor-widget-heading\" data-id=\"88c2197\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">C\u00f3mo funciona la MFA para Active Directory<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83f93dd elementor-widget elementor-widget-text-editor\" data-id=\"83f93dd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">La autenticaci\u00f3n de dos factores en Active Directory funciona a\u00f1adiendo un paso adicional de verificaci\u00f3n al flujo est\u00e1ndar de autenticaci\u00f3n de AD, o bien sustituyendo la contrase\u00f1a est\u00e1ndar de AD por una contrase\u00f1a de un solo uso din\u00e1mica durante el inicio de sesi\u00f3n.<\/span><\/p><p><span style=\"font-weight: 400;\">En el proceso est\u00e1ndar de autenticaci\u00f3n de AD, el usuario introduce su nombre de usuario y contrase\u00f1a, que AD valida contra su base de datos. Con la MFA activada, la autenticaci\u00f3n se realiza con una contrase\u00f1a de un solo uso basada en tiempo (TOTP) generada por una aplicaci\u00f3n autenticadora o entregada mediante un chatbot. <\/span><\/p><p><span style=\"font-weight: 400;\">Existen dos enfoques fundamentalmente distintos para implementarla.<\/span><\/p><h3><b>Enfoque 1: agentes de MFA en el endpoint<\/b><\/h3><p><span style=\"font-weight: 400;\">Las soluciones de MFA tradicionales instalan agentes de software en cada estaci\u00f3n de trabajo, servidor o aplicaci\u00f3n. Cuando un usuario se autentica, el agente intercepta la solicitud y pide el segundo factor. Este enfoque presenta inconvenientes importantes:  <\/span><\/p><table><thead><tr><th><p><b>Limitaci\u00f3n<\/b><\/p><\/th><th><p><b>Impacto<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Hay que instalar el agente en cada endpoint<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Alta carga de despliegue<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Cada aplicaci\u00f3n puede necesitar una integraci\u00f3n distinta<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Se requieren varias soluciones de MFA<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Los agentes necesitan actualizaciones y mantenimiento constantes<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Carga administrativa continua<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Los escenarios sin conexi\u00f3n requieren un manejo especial<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Casos l\u00edmite complejos<\/span><\/p><\/td><\/tr><\/tbody><\/table><h3><b>Enfoque 2: MFA a nivel de directorio (Protectimus DSPA)<\/b><\/h3><p><span style=\"font-weight: 400;\">Protectimus DSPA se integra directamente con Active Directory a nivel de directorio, no a nivel de endpoint ni de aplicaci\u00f3n. En lugar de a\u00f1adir un paso de autenticaci\u00f3n independiente, DSPA sustituye din\u00e1micamente las contrase\u00f1as est\u00e1ticas de los usuarios en AD por contrase\u00f1as de un solo uso basadas en tiempo. <\/span><\/p><p><span style=\"font-weight: 400;\">Los usuarios generan el OTP con la aplicaci\u00f3n Protectimus SMART o mediante chatbots de Telegram, Viber o Facebook Messenger. Como el acceso a la app o al mensajero puede protegerse adicionalmente con un PIN o biometr\u00eda, el proceso de inicio de sesi\u00f3n gana una capa extra de seguridad sin necesidad de software adicional en los endpoints. <\/span><\/p><p><span style=\"font-weight: 400;\">Desde el punto de vista del usuario, simplemente introduce el OTP vigente. Desde el punto de vista de AD, ese c\u00f3digo temporal se convierte en la contrase\u00f1a v\u00e1lida, que cambia autom\u00e1ticamente seg\u00fan el intervalo de rotaci\u00f3n configurado. <\/span><\/p><p><span style=\"font-weight: 400;\">Este enfoque significa que cualquier servicio conectado a Active Directory \u2014Winlogon, RDP, OWA, ADFS y otros\u2014 hereda autom\u00e1ticamente la protecci\u00f3n MFA sin trabajo de integraci\u00f3n adicional.<\/span><\/p><h3><b>D\u00f3nde encaja TOTP junto a FIDO2 y la autenticaci\u00f3n passwordless<\/b><\/h3><p><span style=\"font-weight: 400;\">Una pregunta razonable en 2026 es c\u00f3mo se relaciona la MFA basada en TOTP para Active Directory con m\u00e9todos m\u00e1s recientes resistentes al phishing, como FIDO2, WebAuthn y las passkeys. La respuesta pr\u00e1ctica: los entornos on-premise de Active Directory \u2014especialmente servicios heredados como Winlogon, RDP, LDAP y el acceso a AD por l\u00ednea de comandos\u2014 no admiten FIDO2 de forma nativa en todos los puntos de entrada. La MFA basada en TOTP mediante DSPA cierra hoy esas brechas, funcionando de manera uniforme en todos los servicios autenticados por AD, incluidos aquellos que probablemente nunca contar\u00e1n con soporte nativo de FIDO2. Muchas empresas implementan DSPA para lograr una cobertura amplia de AD y usan FIDO2 de forma selectiva para aplicaciones cr\u00edticas en la nube a trav\u00e9s de ADFS.   <\/span><i><\/i><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-86abc7e padded e-flex e-con-boxed e-con e-parent\" data-id=\"86abc7e\" data-element_type=\"container\" data-e-type=\"container\" id=\"protectimusdspa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-f0f2e30 e-con-full e-flex e-con e-child\" data-id=\"f0f2e30\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-684bcff elementor-widget elementor-widget-heading\" data-id=\"684bcff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Protectimus DSPA: el enfoque \u00fanico para MFA en AD<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4b52e3d elementor-widget elementor-widget-text-editor\" data-id=\"4b52e3d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus DSPA (Dynamic Strong Password Authentication) es la \u00fanica soluci\u00f3n MFA agentless para Active Directory que protege AD a nivel de directorio, extendiendo autom\u00e1ticamente la protecci\u00f3n a todos los servicios conectados a la vez.<\/span><\/p><p><span style=\"font-weight: 400;\">La mayor\u00eda de los proveedores de MFA ofrecen la &#8220;integraci\u00f3n con Active Directory&#8221; como una funci\u00f3n, pero en realidad se refieren a la integraci\u00f3n con ADFS, a una soluci\u00f3n basada en agente para el inicio de sesi\u00f3n de Windows o a un proxy RADIUS para VPN. Cada una de estas opciones protege un \u00fanico punto de entrada. Para cubrir todo el entorno AD, las organizaciones terminan implementando y gestionando varias soluciones de MFA independientes.  <\/span><\/p><p><span style=\"font-weight: 400;\">DSPA funciona de forma fundamentalmente distinta:<\/span><\/p><h3><b>C\u00f3mo funciona DSPA t\u00e9cnicamente<\/b><\/h3><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">La <a href=\"https:\/\/www.protectimus.com\/es\/platform\/\" target=\"_blank\" rel=\"noopener\">Protectimus On-Premise Platform<\/a> con el componente DSPA se instala en infraestructura local<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/dspa\/\" target=\"_blank\" rel=\"noopener\">DSPA se conecta a Active Directory mediante LDAP\/LDAPS<\/a> y requiere permisos para actualizar las contrase\u00f1as de los usuarios<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DSPA actualiza peri\u00f3dicamente las contrase\u00f1as de los usuarios en AD con el valor TOTP vigente<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cuando un usuario se autentica en cualquier servicio conectado a AD, introduce el OTP vigente generado por la aplicaci\u00f3n autenticadora o entregado por un chatbot<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Como el acceso a la aplicaci\u00f3n o al mensajero est\u00e1 protegido con PIN, contrase\u00f1a o biometr\u00eda, la generaci\u00f3n del OTP queda asegurada por un factor de autenticaci\u00f3n adicional<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AD valida la credencial temporal, sin necesidad de una solicitud de MFA independiente ni software adicional en el equipo cliente<\/span><\/li><\/ol><h3><b>Ventajas clave del enfoque DSPA<\/b><\/h3><table><thead><tr><th><p><b>Caracter\u00edstica<\/b><\/p><\/th><th><p><b>MFA tradicional<\/b><\/p><\/th><th><p><b>Protectimus DSPA<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Alcance de la integraci\u00f3n<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Por servicio<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Todo el entorno AD<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Software del lado del cliente<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Requerido<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">No requerido<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Servicios cubiertos<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Integraciones seleccionadas<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Todos los servicios conectados a AD<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Carga administrativa<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Alta (varias integraciones)<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Baja (una sola integraci\u00f3n)<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Soporte de LDAP\/bases de datos<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Limitado<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">S\u00ed (AD\/LDAP\/bases de datos)<\/span><\/p><\/td><\/tr><\/tbody><\/table><p><b>Implicaciones de seguridad: <\/b><span style=\"font-weight: 400;\">Como DSPA opera a nivel de directorio, tambi\u00e9n protege contra una categor\u00eda de ataques que las soluciones basadas en endpoint no pueden cubrir: el acceso directo a AD mediante l\u00ednea de comandos, consultas LDAP o acceso program\u00e1tico. Incluso si un atacante conoce una credencial que fue v\u00e1lida en alg\u00fan momento e intenta autenticarse directamente contra AD sin pasar por la interfaz, la credencial temporal ya no ser\u00e1 v\u00e1lida: el acceso se deniega.<br\/> <\/span><\/p><p><span style=\"font-weight: 400;\">Protectimus DSPA funciona junto con Protectimus On-Premise MFA Platform, que puede implementarse tanto en servidores locales como en la nube privada del cliente, garantizando soberan\u00eda total de los datos sin dependencias externas.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-280411b padded e-flex e-con-boxed e-con e-parent\" data-id=\"280411b\" data-element_type=\"container\" data-e-type=\"container\" id=\"supportedmfa\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2bd5d59 e-con-full e-flex e-con e-child\" data-id=\"2bd5d59\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-347cae5 elementor-widget elementor-widget-heading\" data-id=\"347cae5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">M\u00e9todos de MFA compatibles con Active Directory<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3977085 elementor-widget elementor-widget-text-editor\" data-id=\"3977085\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">La MFA de Protectimus para Windows Active Directory admite dos m\u00e9todos avanzados de segundo factor, dando a las organizaciones flexibilidad para elegir la experiencia de autenticaci\u00f3n adecuada seg\u00fan el grupo de usuarios.<\/span><\/p><p><b>M\u00e9todos de autenticaci\u00f3n disponibles:<\/b><\/p><h3><b>1. Aplicaci\u00f3n m\u00f3vil TOTP (Protectimus Smart OTP)<\/b><\/h3><p><span style=\"font-weight: 400;\">La <a href=\"https:\/\/www.protectimus.com\/es\/token\/smart\/\" target=\"_blank\" rel=\"noopener\">aplicaci\u00f3n Protectimus Smart OTP<\/a> est\u00e1 disponible para Android e iOS. Genera contrase\u00f1as de un solo uso basadas en tiempo (TOTP) y admite intervalos de tiempo configurables (30, 60, 90 segundos, o cualquier m\u00faltiplo de 30 hasta 3000 segundos). Esta flexibilidad es esencial para DSPA, donde el intervalo del OTP debe coincidir con el intervalo de rotaci\u00f3n de contrase\u00f1a configurado en AD.  <\/span><\/p><p><b>Caracter\u00edsticas:<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Copia de seguridad en la nube para recuperar el token<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protecci\u00f3n con PIN y biometr\u00eda<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Transferencia sencilla del token a un dispositivo nuevo<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compatible con cualquier est\u00e1ndar OATH TOTP<\/span><\/li><\/ul><h3><b>2. Protectimus BOT<\/b><\/h3><p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/token\/bot\/\" target=\"_blank\" rel=\"noopener\">Entrega de OTP mediante chatbots de Telegram, Viber o Facebook Messenger<\/a>, una alternativa moderna al SMS que funciona por conexi\u00f3n a internet sin depender del operador m\u00f3vil. Los usuarios pueden proteger adicionalmente el acceso a la app de mensajer\u00eda con contrase\u00f1a, PIN o biometr\u00eda, a\u00f1adiendo una capa m\u00e1s de seguridad al proceso de autenticaci\u00f3n. <\/span><\/p><h3><b>C\u00f3mo elegir el m\u00e9todo adecuado para DSPA<\/b><\/h3><p><span style=\"font-weight: 400;\">En las implementaciones de DSPA, los usuarios pueden autenticarse con la aplicaci\u00f3n Protectimus SMART o con los chatbots de Protectimus BOT. Ambos m\u00e9todos admiten intervalos TOTP configurables que pueden sincronizarse con el intervalo de rotaci\u00f3n de contrase\u00f1a de DSPA, y pueden protegerse adicionalmente con PIN o biometr\u00eda. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a29b829 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a29b829\" data-element_type=\"container\" data-e-type=\"container\" id=\"protectedautomat\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-1dc9ec2 e-con-full e-flex e-con e-child\" data-id=\"1dc9ec2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-131348d elementor-widget elementor-widget-heading\" data-id=\"131348d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Qu\u00e9 servicios quedan protegidos autom\u00e1ticamente<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5266633 elementor-widget elementor-widget-text-editor\" data-id=\"5266633\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Cuando Protectimus DSPA se integra con Active Directory, la autenticaci\u00f3n basada en OTP se aplica autom\u00e1ticamente a los servicios que se autentican directamente contra AD, sin necesidad de agentes independientes ni integraciones por servicio.<\/span><\/p><p><span style=\"font-weight: 400;\">Este es el valor central de DSPA: una \u00fanica integraci\u00f3n con Active Directory protege varios servicios conectados a la vez.<\/span><\/p><p><span style=\"font-weight: 400;\">Esto es lo que se protege autom\u00e1ticamente:<br><\/span><\/p><p><b>Autenticaci\u00f3n de Windows<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/winlogon\/\" target=\"_blank\" rel=\"noopener\">Winlogon: inicio de sesi\u00f3n en el escritorio de Windows<\/a> (equipos unidos al dominio)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RDP (Remote Desktop Protocol): acceso remoto a servidores y estaciones de trabajo Windows<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Autenticaci\u00f3n de Windows Server: acceso a nivel de servidor<\/span><\/span><\/li><\/ul><p><b><br>Correo y colaboraci\u00f3n de Microsoft<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/owa\/\" target=\"_blank\" rel=\"noopener\">OWA (Outlook Web Access):<\/a> acceso al correo web mediante autenticaci\u00f3n de Active Directory<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Exchange ActiveSync: sincronizaci\u00f3n de correo en dispositivos m\u00f3viles<\/span><\/span><\/li><\/ul><p><b><br>Servicios de directorio<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Autenticaci\u00f3n LDAP: cualquier aplicaci\u00f3n que env\u00ede consultas LDAP a AD<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Acceso a AD por l\u00ednea de comandos: acceso program\u00e1tico mediante la l\u00ednea de comandos de Windows o scripts<\/span><\/span><\/li><\/ul><p><b><br>Servicios de federaci\u00f3n<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">ADFS 3.0 y 4.0: los servicios federados a trav\u00e9s de AD FS heredan la autenticaci\u00f3n protegida por DSPA, ya que AD FS depende de Active Directory<\/span><\/span><\/li><\/ul><p><b><br>Servicios adicionales protegidos mediante otros componentes de Protectimus:<\/b><\/p><p><span style=\"font-weight: 400;\">Servicios conectados v\u00eda RADIUS (con el <a href=\"https:\/\/www.protectimus.com\/es\/guides\/radius-2fa\/\" target=\"_blank\" rel=\"noopener\">componente independiente Protectimus RADIUS<\/a>):<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Soluciones VPN (Cisco, Citrix, FortiGate, SonicWALL, OpenVPN, etc.)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Autenticaci\u00f3n Wi-Fi (802.1X)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firewalls y dispositivos de red<\/span><\/li><\/ul><h3><b>Comparaci\u00f3n de cobertura<\/b><\/h3><table><thead><tr><th><b>Servicio<\/b><\/th><th><b>MFA tradicional de endpoint<\/b><\/th><th><b>Protectimus DSPA<\/b><\/th><\/tr><\/thead><tbody><tr><th><span style=\"font-weight: 400;\">Winlogon<\/span><\/th><th><span style=\"font-weight: 400;\">Requiere agente<\/span><\/th><th><span style=\"font-weight: 400;\">\u2713 Autom\u00e1tico<\/span><\/th><\/tr><tr><span style=\"font-weight: 400;\"><\/span><th>RDP<\/th><th><span style=\"font-weight: 400;\">Requiere agente<\/span><\/th><th><span style=\"font-weight: 400;\">\u2713 Autom\u00e1tico<\/span><\/th><\/tr><tr><th><span style=\"font-weight: 400;\">OWA<\/span><\/th><th><span style=\"font-weight: 400;\">Requiere agente<\/span><\/th><th><span style=\"font-weight: 400;\">\u2713 Autom\u00e1tico<\/span><\/th><\/tr><tr><th><span style=\"font-weight: 400;\">Acceso LDAP<\/span><\/th>\u2717 <th><span style=\"font-weight: 400;\">No cubierto<\/span><\/th><th><span style=\"font-weight: 400;\">\u2713 Autom\u00e1tico<\/span><\/th><\/tr><tr><th><span style=\"font-weight: 400;\">Acceso a CLI AD<\/span><\/th><th><span style=\"font-weight: 400;\">\u2717 No cubierto<\/span><\/th><th><span style=\"font-weight: 400;\">\u2713 Autom\u00e1tico<\/span><\/th><\/tr><tr><th><span style=\"font-weight: 400;\">ADFS<\/span><\/th><th><span style=\"font-weight: 400;\">\u2717 No cubierto<\/span><\/th><th><span style=\"font-weight: 400;\">\u2713 Autom\u00e1tico<\/span><\/th><\/tr><tr><td><span style=\"font-weight: 400;\">Aplicaciones federadas con ADFS<\/span><\/td><td><span style=\"font-weight: 400;\">Necesita un complemento<\/span><\/td><td><span style=\"font-weight: 400;\">\u2713 Heredan la autenticaci\u00f3n de AD FS<\/span><\/td><\/tr><\/tbody><\/table><p><span style=\"font-weight: 400;\">La implicaci\u00f3n pr\u00e1ctica: las organizaciones que usan MFA tradicional suelen tener brechas de cobertura de las que ni siquiera son conscientes. El inicio de sesi\u00f3n en Windows de un usuario puede estar protegido con MFA, pero el acceso LDAP directo a esa misma cuenta puede no estarlo. DSPA cierra estas brechas al operar en el origen.  <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-16797b4 padded e-flex e-con-boxed e-con e-parent\" data-id=\"16797b4\" data-element_type=\"container\" data-e-type=\"container\" id=\"activemfaforadfs\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-bb86bc5 e-con-full e-flex e-con e-child\" data-id=\"bb86bc5\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-891beb3 elementor-widget elementor-widget-heading\" data-id=\"891beb3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">MFA para Active Directory mediante ADFS<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7f6098 elementor-widget elementor-widget-text-editor\" data-id=\"d7f6098\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus tambi\u00e9n ofrece un <a href=\"https:\/\/www.protectimus.com\/es\/adfs\/\" target=\"_blank\" rel=\"noopener\">componente dedicado de ADFS<\/a> para organizaciones que usan Active Directory Federation Services, permitiendo habilitar MFA para todas las aplicaciones federadas mediante ADFS en menos de 15 minutos.<\/span><\/p><p><span style=\"font-weight: 400;\">ADFS (Active Directory Federation Services) es la soluci\u00f3n de federaci\u00f3n de identidades de Microsoft que permite el inicio de sesi\u00f3n \u00fanico (SSO) en servicios en la nube y aplicaciones web. Cuando la MFA se configura a nivel de ADFS, se aplica a todos los servicios federados a trav\u00e9s de ADFS, sin necesidad de integraci\u00f3n por aplicaci\u00f3n. <\/span><\/p><p><b>Versiones de ADFS compatibles:<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/guides\/adfs-3-0\/\" target=\"_blank\" rel=\"noopener\">ADFS 3.0<\/a> (Windows Server 2012 R2)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/guides\/adfs-4-0\/\" target=\"_blank\" rel=\"noopener\">ADFS 4.0<\/a> (Windows Server 2016)<\/span><\/span><\/li><\/ul><p><b><br>Servicios que pueden protegerse con Protectimus + ADFS:<\/b><\/p><p><span style=\"font-weight: 400;\">Servicios en la nube: AWS, Microsoft 365, Salesforce, Dropbox, GitHub, Slack, Zoom, Webex, Jira SSO, Workday, Zendesk y decenas m\u00e1s.<\/span><\/p><p><b>Proceso de integraci\u00f3n:<\/b><\/p><ol><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Reg\u00edstrese en Protectimus Cloud o instale Protectimus On-Premise Platform<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cree un recurso y a\u00f1ada usuarios en Protectimus<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Descargue el instalador de Protectimus ADFS<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ejecute el instalador en su servidor ADFS (requiere privilegios de administrador)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Introduzca la URL de la API, el usuario, la clave de API y el ID de recurso durante la instalaci\u00f3n<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Configure ADFS para usar Protectimus como proveedor de autenticaci\u00f3n adicional<\/span><\/span><\/li><\/ol><p><b>Nota t\u00e9cnica importante: <\/b><span style=\"font-weight: 400;\">Los usuarios en Protectimus deben tener inicios de sesi\u00f3n con el formato login@dominio.com para coincidir con el formato de identidad de ADFS. Este es un error de configuraci\u00f3n habitual que provoca fallos de autenticaci\u00f3n. <\/span><\/p><p><b>Combinaci\u00f3n ADFS + DSPA: <\/b><span style=\"font-weight: 400;\">Para lograr la m\u00e1xima cobertura, las organizaciones pueden implementar tanto DSPA (para la autenticaci\u00f3n directa en AD) como el componente Protectimus ADFS (para los servicios federados en la nube). Esta combinaci\u00f3n garantiza que todos los puntos de entrada a la infraestructura de identidad corporativa exijan MFA, sin brechas. <\/span><i><\/i><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9c8d6af padded e-flex e-con-boxed e-con e-parent\" data-id=\"9c8d6af\" data-element_type=\"container\" data-e-type=\"container\" id=\"deployoptions\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-628fed7 e-con-full e-flex e-con e-child\" data-id=\"628fed7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4221a91 elementor-widget elementor-widget-heading\" data-id=\"4221a91\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Opciones de implementaci\u00f3n: nube frente a on-premise<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-367d754 elementor-widget elementor-widget-text-editor\" data-id=\"367d754\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">La MFA de Protectimus para Active Directory est\u00e1 disponible tanto como servicio en la nube como en forma de plataforma totalmente on-premise. Componentes como la integraci\u00f3n de MFA con ADFS admiten ambos modelos de implementaci\u00f3n, mientras que Protectimus DSPA est\u00e1 disponible exclusivamente con la plataforma on-premise, que puede desplegarse en infraestructura local o en un entorno de nube privada. <\/span><\/p><h3><b>Implementaci\u00f3n en la nube (SaaS)<\/b><\/h3><p><span style=\"font-weight: 400;\">El servicio en la nube de Protectimus no requiere infraestructura de servidores en el lado del cliente. La plataforma de MFA est\u00e1 alojada y mantenida por Protectimus, y ADFS se conecta a ella mediante API. Es la v\u00eda m\u00e1s r\u00e1pida hacia la implementaci\u00f3n.  <\/span><\/p><p><b>Ventajas:<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">No requiere hardware de servidor<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Actualizaciones y mantenimiento autom\u00e1ticos<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implementaci\u00f3n r\u00e1pida (horas, no d\u00edas)<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Modelo de pago por uso<\/span><\/span><\/li><\/ul><p><b><br>Aspectos a considerar:<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Los datos de autenticaci\u00f3n pasan por la infraestructura en la nube de Protectimus<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Requiere conectividad a internet<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">No es adecuado para entornos air-gapped<\/span><\/span><\/li><\/ul><h3><b>Implementaci\u00f3n on-premise<\/b><\/h3><p><span style=\"font-weight: 400;\">La plataforma Protectimus On-Premise se instala dentro de la propia infraestructura del cliente, ya sea en servidores f\u00edsicos o en una nube privada. Ofrece soberan\u00eda total de los datos y admite implementaciones en redes aisladas. <\/span><\/p><p><b>Requisitos t\u00e9cnicos para la instalaci\u00f3n on-premise:<\/b><\/p><table><thead><tr><th><p><b>Componente<\/b><\/p><\/th><th><p><b>Requisito<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Tipo de instancia<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">2 n\u00facleos de CPU, 8 GB de RAM<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Sistema operativo<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Linux (principal), FreeBSD, Windows<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Almacenamiento<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">100 GB por instancia al mes<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Tr\u00e1fico de red<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">1.000 GB al mes<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Alta disponibilidad<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Cl\u00faster m\u00ednimo de 3 nodos con HAProxy<\/span><\/p><\/td><\/tr><\/tbody><\/table><p>Para instrucciones de instalaci\u00f3n paso a paso, consulte la gu\u00eda de instalaci\u00f3n de <a href=\"https:\/\/www.protectimus.com\/es\/guides\/on-premise-platform\/\" target=\"_blank\" rel=\"noopener\">Protectimus On-Premise Platform<\/a>.<\/p><p><b>Caracter\u00edsticas de la implementaci\u00f3n on-premise:<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Control total sobre todos los datos de autenticaci\u00f3n<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Soporte de entornos multidominio<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clustering y alta disponibilidad<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replicaci\u00f3n y copia de seguridad de datos<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Opci\u00f3n de implementaci\u00f3n en nube privada<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Soporte de redes air-gapped<\/span><\/span><\/li><\/ul><h3><b>Implementaci\u00f3n en nube privada<\/b><\/h3><p><span style=\"font-weight: 400;\">Una opci\u00f3n h\u00edbrida en la que la plataforma Protectimus se despliega en la infraestructura de nube privada del cliente (instancias privadas de AWS, Azure, Google Cloud). Combina la escalabilidad de la nube con el control de datos propio de las implementaciones on-premise. <\/span><\/p><p><span style=\"font-weight: 400;\">Para la mayor\u00eda de los sectores regulados \u2014servicios financieros, salud, sector p\u00fablico\u2014 la implementaci\u00f3n on-premise o en nube privada suele ser la opci\u00f3n preferida por los requisitos de residencia de datos.<\/span><\/p><p><b>\u00bfNo est\u00e1 seguro de qu\u00e9 modelo de implementaci\u00f3n se ajusta a su entorno? <\/b><span style=\"font-weight: 400;\">Los arquitectos de soluciones de Protectimus pueden revisar la topolog\u00eda de su AD, sus requisitos de cumplimiento y su infraestructura existente para recomendar el camino adecuado. Solicite una consultor\u00eda de arquitectura gratuita. <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dd147b2 padded e-flex e-con-boxed e-con e-parent\" data-id=\"dd147b2\" data-element_type=\"container\" data-e-type=\"container\" id=\"multidomain\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-c9b7b25 e-con-full e-flex e-con e-child\" data-id=\"c9b7b25\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fad9de1 elementor-widget elementor-widget-heading\" data-id=\"fad9de1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Entornos multidominio y de gran empresa<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-78865c0 elementor-widget elementor-widget-text-editor\" data-id=\"78865c0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">La MFA de Protectimus para Microsoft AD admite plenamente entornos multidominio, lo que la hace apta para grandes empresas con estructuras de bosque AD complejas y controladores de dominio distribuidos.<\/span><\/p><p><span style=\"font-weight: 400;\">Los entornos empresariales de Active Directory suelen incluir varios dominios dentro de un mismo bosque, relaciones de confianza entre bosques y controladores de dominio distribuidos geogr\u00e1ficamente. Las soluciones de MFA tradicionales rinden mal en estos entornos porque requieren configuraci\u00f3n independiente para cada dominio o dependen de agentes que hay que desplegar en miles de equipos. <\/span><\/p><h3><b>Soporte multidominio de Protectimus:<\/b><\/h3><p><span style=\"font-weight: 400;\">La plataforma Protectimus On-Premise est\u00e1 dise\u00f1ada espec\u00edficamente para entornos multidominio. Entre sus capacidades clave: <\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Autenticaci\u00f3n entre dominios:<\/b> <span style=\"font-weight: 400;\">usuarios de distintos dominios dentro de la misma organizaci\u00f3n pueden autenticarse a trav\u00e9s de una \u00fanica implementaci\u00f3n de Protectimus<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Soporte de confianza entre bosques:<\/b> <span style=\"font-weight: 400;\">los flujos de autenticaci\u00f3n a trav\u00e9s de bosques AD de confianza se gestionan correctamente<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Gesti\u00f3n centralizada:<\/b> <span style=\"font-weight: 400;\">todos los usuarios, tokens y pol\u00edticas se administran desde una \u00fanica consola de Protectimus, sin importar el dominio<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Pol\u00edticas basadas en grupos:<\/b> la MFA puede aplicarse a grupos espec\u00edficos de AD en lugar de a todos los usuarios, \u00fatil para despliegues por fases o para reforzar la seguridad de las cuentas con privilegios<br\/><br\/><\/li><\/ul><h3><b>Implementaci\u00f3n selectiva de MFA<\/b><\/h3><p><span style=\"font-weight: 400;\">Un requisito habitual en las grandes empresas es aplicar la MFA a grupos de usuarios espec\u00edficos \u2014administradores de TI, cuentas con privilegios, trabajadores remotos\u2014 mientras el resto sigue autentic\u00e1ndose con la contrase\u00f1a est\u00e1ndar de Active Directory durante un periodo de transici\u00f3n. Protectimus DSPA lo permite mediante segmentaci\u00f3n por grupos de AD. <\/span><\/p><h3><b>Alta disponibilidad y clustering<\/b><\/h3><p><span style=\"font-weight: 400;\">Para implementaciones empresariales, Protectimus On-Premise admite una arquitectura en cl\u00faster:<\/span><\/p><table><thead><tr><th><p><b>Configuraci\u00f3n<\/b><\/p><\/th><th><p><b>Descripci\u00f3n<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Cl\u00faster est\u00e1ndar<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">M\u00ednimo 3 nodos para alta disponibilidad<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Replicaci\u00f3n maestro-esclavo<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Replicaci\u00f3n de datos en tiempo real entre nodos<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Balanceo de carga con HAProxy<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Distribuci\u00f3n del tr\u00e1fico y monitorizaci\u00f3n de estado<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Failover autom\u00e1tico<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Conmutaci\u00f3n transparente si un nodo falla<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Copia de seguridad y restauraci\u00f3n<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Copias de seguridad programadas de todos los datos de autenticaci\u00f3n<\/span><\/p><\/td><\/tr><\/tbody><\/table><p><span style=\"font-weight: 400;\">Esta arquitectura garantiza que la MFA nunca se convierta en un \u00fanico punto de fallo en la infraestructura de autenticaci\u00f3n.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a2442ac padded e-flex e-con-boxed e-con e-parent\" data-id=\"a2442ac\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-d2891c1 e-con-full e-flex e-con e-child\" data-id=\"d2891c1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f2847f8 elementor-widget elementor-widget-heading\" data-id=\"f2847f8\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"howtosetup\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">C\u00f3mo configurar la MFA para Active Directory con Protectimus<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-32a2622 elementor-widget elementor-widget-text-editor\" data-id=\"32a2622\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Configurar la MFA de Protectimus para Active Directory implica cuatro pasos principales: instalaci\u00f3n de la plataforma, configuraci\u00f3n de DSPA, sincronizaci\u00f3n de usuarios y pruebas.<\/span><\/p><p><b>Requisitos previos:<\/b><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Active Directory u otro directorio compatible con LDAP<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Acceso administrativo al directorio<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Un servidor o entorno de nube privada que cumpla los requisitos para desplegar Protectimus On-Premise Platform<br><br><\/span><\/li><\/ul><p><b>Configuraci\u00f3n paso a paso:<br><\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-6b62c969 e-con-full e-flex e-con e-child\" data-id=\"6b62c969\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-1053c6f5 e-con-full e-flex e-con e-child\" data-id=\"1053c6f5\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-37130881 e-con-full e-flex e-con e-child\" data-id=\"37130881\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-5dd6949d elementor-widget elementor-widget-image\" data-id=\"5dd6949d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/1.svg\" class=\"attachment-full size-full wp-image-17820\" alt=\"Step 1 icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c30db46 elementor-widget elementor-widget-heading\" data-id=\"7c30db46\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Paso 1: registrarse en Protectimus<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-773962ca elementor-widget elementor-widget-text-editor\" data-id=\"773962ca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Reg\u00edstrese en Protectimus Cloud Service. Para ello, <a target=\"_blank\" target=\"_blank\" href=\"https:\/\/service.protectimus.com\/register\" target=\"_blank\" rel=\"noopener\">siga este enlace<\/a>, complete el formulario de registro y confirme su direcci\u00f3n de correo electr\u00f3nico. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1bc0324f e-con-full e-flex e-con e-child\" data-id=\"1bc0324f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-631ac250 e-con-full e-flex e-con e-child\" data-id=\"631ac250\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-190f7b00 elementor-widget elementor-widget-image\" data-id=\"190f7b00\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/2.svg\" class=\"attachment-full size-full wp-image-17821\" alt=\"Step 2 icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1cc1021d elementor-widget elementor-widget-heading\" data-id=\"1cc1021d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Paso 2: activar un plan de pago<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-63be4293 elementor-widget elementor-widget-text-editor\" data-id=\"63be4293\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Para utilizar Protectimus Cloud Service y habilitar el acceso a la API, deber\u00e1 activar un plan de servicio. Para ello, vaya a la secci\u00f3n \u00ab<a target=\"_blank\" target=\"_blank\" href=\"https:\/\/service.protectimus.com\/panel\/tariffs\" target=\"_blank\" rel=\"noopener\">Planes de servicio<\/a>\u00bb (Payment plans). <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-592be36b e-con-full e-flex e-con e-child\" data-id=\"592be36b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-5e6425dc e-con-full e-flex e-con e-child\" data-id=\"5e6425dc\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-16f8724f elementor-widget elementor-widget-image\" data-id=\"16f8724f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/3.svg\" class=\"attachment-full size-full wp-image-17822\" alt=\"Step 3 icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2a18270b elementor-widget elementor-widget-heading\" data-id=\"2a18270b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Paso 3: crear un recurso<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-11977e49 elementor-widget elementor-widget-text-editor\" data-id=\"11977e49\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tLos recursos se utilizan para agrupar l\u00f3gicamente usuarios y tokens OTP. Para crear un recurso, haga clic en \u00abRecursos\u00bb (Resources) en el men\u00fa lateral izquierdo de su cuenta y, a continuaci\u00f3n, seleccione \u00abA\u00f1adir recurso\u00bb (Add resource) en la parte superior de la tabla. \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4436cffb e-con-full e-flex e-con e-child\" data-id=\"4436cffb\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-28583375 e-con-full e-flex e-con e-child\" data-id=\"28583375\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2661672 elementor-widget elementor-widget-image\" data-id=\"2661672\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/4.svg\" class=\"attachment-full size-full wp-image-17823\" alt=\"Step 4 icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3067223 elementor-widget elementor-widget-heading\" data-id=\"3067223\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Paso 4: a\u00f1adir usuarios y tokens OTP<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6fc372e7 elementor-widget elementor-widget-text-editor\" data-id=\"6fc372e7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tCree usuarios y tokens OTP, y as\u00edgnelos al recurso creado anteriormente. Recuerde que los usuarios deben utilizar nombres de inicio de sesi\u00f3n con el formato login@domain.com \t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9f65fa1 elementor-widget elementor-widget-text-editor\" data-id=\"9f65fa1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h3><b>Cronograma t\u00edpico de implementaci\u00f3n<\/b><\/h3><table><thead><tr><th><p><b>Fase<\/b><\/p><\/th><th><p><b>Duraci\u00f3n<\/b><\/p><\/th><\/tr><\/thead><tbody><tr><td><p><span style=\"font-weight: 400;\">Configuraci\u00f3n de la plataforma<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">1\u20132 horas<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Configuraci\u00f3n de DSPA<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">1\u20132 horas<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Pruebas piloto<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Varias horas<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Despliegue en toda la organizaci\u00f3n<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">Inmediato tras la validaci\u00f3n<\/span><\/p><\/td><\/tr><tr><td><p><span style=\"font-weight: 400;\">Tiempo total de implementaci\u00f3n<\/span><\/p><\/td><td><p><span style=\"font-weight: 400;\">1\u20132 d\u00edas<\/span><\/p><\/td><\/tr><\/tbody><\/table><p><span style=\"font-weight: 400;\">Para la integraci\u00f3n con ADFS en particular, el componente Protectimus ADFS puede instalarse y configurarse en menos de 15 minutos usando el instalador provisto y la gu\u00eda paso a paso.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a9cb282 padded e-flex e-con-boxed e-con e-parent\" data-id=\"a9cb282\" data-element_type=\"container\" data-e-type=\"container\" id=\"faq\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-7659ffd elementor-widget elementor-widget-heading\" data-id=\"7659ffd\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Preguntas frecuentes<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-dc81e4c e-con-full padded e-flex e-con e-child\" data-id=\"dc81e4c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-fb2596d e-con-full faq-container e-flex e-con e-child\" data-id=\"fb2596d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-412fa06 plus-right elementor-widget elementor-widget-n-accordion\" data-id=\"412fa06\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;default_state&quot;:&quot;all_collapsed&quot;,&quot;max_items_expended&quot;:&quot;one&quot;,&quot;n_accordion_animation_duration&quot;:{&quot;unit&quot;:&quot;ms&quot;,&quot;size&quot;:400,&quot;sizes&quot;:[]}}\" data-widget_type=\"nested-accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"e-n-accordion\" aria-label=\"Accordion. Open links with Enter or Space, close with Escape, and navigate with Arrow Keys\">\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6830\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"1\" tabindex=\"0\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6830\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfLa MFA de Protectimus para Active Directory requiere instalar software en el equipo de cada usuario? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6830\" class=\"elementor-element elementor-element-ea1991a e-con-full e-flex e-con e-child\" data-id=\"ea1991a\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-8bad61c elementor-widget elementor-widget-text-editor\" data-id=\"8bad61c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">No. Esta es una de las principales ventajas del enfoque de Protectimus DSPA. Como DSPA se integra a nivel de Active Directory en lugar de a nivel de endpoint, no es necesario instalar ni mantener software del lado del cliente en las estaciones de trabajo de los usuarios. El componente DSPA se despliega como parte de Protectimus On-Premise Platform en un controlador de dominio o en un servidor dedicado con acceso a Active Directory. Los usuarios simplemente introducen el OTP vigente generado en la app autenticadora o entregado mediante un chatbot. Esto reduce notablemente la complejidad de la implementaci\u00f3n y la carga de mantenimiento en comparaci\u00f3n con las soluciones de MFA tradicionales basadas en agentes.    <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6831\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"2\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6831\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfSe puede aplicar la MFA a grupos espec\u00edficos de Active Directory en lugar de a todos los usuarios? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6831\" class=\"elementor-element elementor-element-b2bdc68 e-con-full e-flex e-con e-child\" data-id=\"b2bdc68\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f30747e elementor-widget elementor-widget-text-editor\" data-id=\"f30747e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">S\u00ed. Protectimus DSPA admite pol\u00edticas de MFA basadas en grupos, lo que permite a los administradores aplicar la autenticaci\u00f3n de dos factores solo a determinados grupos de seguridad de AD. Esto resulta especialmente \u00fatil para despliegues por fases, empezando por los administradores de TI y las cuentas con privilegios antes de extenderlo al resto de la organizaci\u00f3n, o para aplicar de forma permanente requisitos de seguridad m\u00e1s estrictos a las cuentas de mayor riesgo. Los usuarios que no pertenecen al grupo con MFA activada siguen autentic\u00e1ndose con su contrase\u00f1a est\u00e1ndar hasta que se les a\u00f1ade al grupo protegido.   <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6832\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"3\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6832\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfQu\u00e9 ocurre si un usuario pierde su token o su aplicaci\u00f3n autenticadora? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6832\" class=\"elementor-element elementor-element-0787040 e-con-full e-flex e-con e-child\" data-id=\"0787040\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-9eb7aff elementor-widget elementor-widget-text-editor\" data-id=\"9eb7aff\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Protectimus ofrece varias opciones de recuperaci\u00f3n. Los administradores pueden desactivar temporalmente la MFA para un usuario concreto desde la consola de administraci\u00f3n, permitiendo el acceso con la contrase\u00f1a est\u00e1tica mientras se emite un nuevo token. La app Protectimus Smart OTP admite copia de seguridad en la nube, lo que permite a los usuarios restaurar sus tokens en un dispositivo nuevo sin intervenci\u00f3n del administrador. Para otros casos de p\u00e9rdida de token, puede emitirse y asignarse un token de reemplazo desde la consola de administraci\u00f3n.   <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6833\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"4\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6833\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfEs compatible la MFA de Protectimus para Active Directory con entornos h\u00edbridos de Azure AD (Entra ID)? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6833\" class=\"elementor-element elementor-element-b3373c0 e-con-full e-flex e-con e-child\" data-id=\"b3373c0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6ef49d2 elementor-widget elementor-widget-text-editor\" data-id=\"6ef49d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">S\u00ed. Las organizaciones que ejecutan entornos h\u00edbridos con Active Directory on-premise y Microsoft Entra ID pueden usar Protectimus para proteger el componente local de AD. La MFA de Protectimus tambi\u00e9n puede integrarse con AD FS, lo que permite aplicar MFA a los flujos de autenticaci\u00f3n que dependen de la federaci\u00f3n de Active Directory.  <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6834\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"5\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6834\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfC\u00f3mo se compara la MFA de Protectimus para Active Directory con las llaves FIDO2 y las passkeys? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6834\" class=\"elementor-element elementor-element-3e2c10e e-con-full e-flex e-con e-child\" data-id=\"3e2c10e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1ee304 elementor-widget elementor-widget-text-editor\" data-id=\"e1ee304\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">FIDO2 y las passkeys son m\u00e9todos de autenticaci\u00f3n resistentes al phishing dise\u00f1ados principalmente para aplicaciones web modernas y servicios en la nube. Funcionan bien con aplicaciones federadas mediante ADFS y con escenarios de Microsoft Entra ID, pero tienen un soporte nativo limitado en los puntos de entrada heredados de Active Directory on-premise, incluidos Winlogon (sobre todo en versiones antiguas de Windows Server), RDP, las consultas LDAP y el acceso a AD por l\u00ednea de comandos. Protectimus DSPA cubre todos estos puntos de manera uniforme con MFA basada en TOTP. En 2026, la mayor\u00eda de las empresas adoptan un enfoque por capas: Protectimus DSPA para lograr una cobertura amplia de MFA en Active Directory en todos los servicios conectados a AD, y FIDO2\/passkeys de forma selectiva para las aplicaciones cr\u00edticas en la nube accesibles a trav\u00e9s de ADFS o Entra ID. Ambos enfoques se complementan, no compiten entre s\u00ed.    <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6835\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"6\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6835\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfC\u00f3mo protege la MFA de Protectimus contra los ataques pass-the-hash y pass-the-ticket? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6835\" class=\"elementor-element elementor-element-67bff32 e-con-full e-flex e-con e-child\" data-id=\"67bff32\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ed5da62 elementor-widget elementor-widget-text-editor\" data-id=\"ed5da62\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Los ataques pass-the-hash (PtH) y pass-the-ticket (PtT) capturan tokens de autenticaci\u00f3n o hashes de contrase\u00f1a de la memoria y los reutilizan para autenticarse sin conocer la contrase\u00f1a real. Protectimus DSPA eleva considerablemente la dificultad de estos ataques: como la contrase\u00f1a de Active Directory se sustituye continuamente por una contrase\u00f1a de un solo uso basada en tiempo (TOTP), un hash o ticket capturado solo es v\u00e1lido durante la ventana del OTP vigente. Un atacante que captura un hash en el segundo 1 de una ventana de 30 segundos dispone, como mucho, de 29 segundos para usarlo antes de que la contrase\u00f1a cambie y el hash quede invalidado. Esto reduce dr\u00e1sticamente la explotabilidad pr\u00e1ctica de estas t\u00e9cnicas de ataque en comparaci\u00f3n con entornos que solo usan contrase\u00f1as est\u00e1ticas.   <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t\t<details id=\"e-n-accordion-item-6836\" class=\"e-n-accordion-item\" >\n\t\t\t\t<summary class=\"e-n-accordion-item-title\" data-accordion-index=\"7\" tabindex=\"-1\" aria-expanded=\"false\" aria-controls=\"e-n-accordion-item-6836\" >\n\t\t\t\t\t<span class='e-n-accordion-item-title-header'><h3 class=\"e-n-accordion-item-title-text\"> \u00bfQu\u00e9 marcos de cumplimiento ayuda a satisfacer la MFA de Protectimus para AD? <\/h3><\/span>\n\t\t\t\t\t\t\t<span class='e-n-accordion-item-title-icon'>\n\t\t\t<span class='e-opened' ><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"2\" viewBox=\"0 0 24 2\" fill=\"none\"><path d=\"M24 1L5.96046e-08 0.999999\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t\t<span class='e-closed'><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"24\" height=\"24\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M12 0V24\" stroke=\"#111111\" stroke-width=\"2\"><\/path><path d=\"M24 12L5.96046e-08 12\" stroke=\"#111111\" stroke-width=\"2\"><\/path><\/svg><\/span>\n\t\t<\/span>\n\n\t\t\t\t\t\t<\/summary>\n\t\t\t\t<div role=\"region\" aria-labelledby=\"e-n-accordion-item-6836\" class=\"elementor-element elementor-element-a41023b e-con-full e-flex e-con e-child\" data-id=\"a41023b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2a36881 elementor-widget elementor-widget-text-editor\" data-id=\"2a36881\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">La MFA de Protectimus para Active Directory aborda directamente los requisitos de MFA de varios marcos de cumplimiento. NIST SP 800-63B exige autenticaci\u00f3n multifactor para los sistemas que manejan datos sensibles. PCI DSS v4.0 (requisito 8.4) exige MFA para todo acceso al entorno de datos de titulares de tarjetas. HIPAA requiere controles de acceso t\u00e9cnicos para los sistemas que contienen informaci\u00f3n sanitaria protegida. SOC 2 Type II suele exigir MFA como parte de los controles de acceso l\u00f3gico evaluados durante la auditor\u00eda. ISO 27001, en el Anexo A, control A.9.4, aborda el control de acceso a sistemas y aplicaciones. Protectimus es una soluci\u00f3n certificada por OATH, lo que respalda las afirmaciones de cumplimiento en entornos que requieren est\u00e1ndares de autenticaci\u00f3n certificados.      <\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/details>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"\\u00bfLa MFA de Protectimus para Active Directory requiere instalar software en el equipo de cada usuario?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. Esta es una de las principales ventajas del enfoque de Protectimus DSPA. Como DSPA se integra a nivel de Active Directory en lugar de a nivel de endpoint, no es necesario instalar ni mantener software del lado del cliente en las estaciones de trabajo de los usuarios. El componente DSPA se despliega como parte de Protectimus On-Premise Platform en un controlador de dominio o en un servidor dedicado con acceso a Active Directory. Los usuarios simplemente introducen el OTP vigente generado en la app autenticadora o entregado mediante un chatbot. Esto reduce notablemente la complejidad de la implementaci\\u00f3n y la carga de mantenimiento en comparaci\\u00f3n con las soluciones de MFA tradicionales basadas en agentes.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfSe puede aplicar la MFA a grupos espec\\u00edficos de Active Directory en lugar de a todos los usuarios?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"S\\u00ed. Protectimus DSPA admite pol\\u00edticas de MFA basadas en grupos, lo que permite a los administradores aplicar la autenticaci\\u00f3n de dos factores solo a determinados grupos de seguridad de AD. Esto resulta especialmente \\u00fatil para despliegues por fases, empezando por los administradores de TI y las cuentas con privilegios antes de extenderlo al resto de la organizaci\\u00f3n, o para aplicar de forma permanente requisitos de seguridad m\\u00e1s estrictos a las cuentas de mayor riesgo. Los usuarios que no pertenecen al grupo con MFA activada siguen autentic\\u00e1ndose con su contrase\\u00f1a est\\u00e1ndar hasta que se les a\\u00f1ade al grupo protegido.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfQu\\u00e9 ocurre si un usuario pierde su token o su aplicaci\\u00f3n autenticadora?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Protectimus ofrece varias opciones de recuperaci\\u00f3n. Los administradores pueden desactivar temporalmente la MFA para un usuario concreto desde la consola de administraci\\u00f3n, permitiendo el acceso con la contrase\\u00f1a est\\u00e1tica mientras se emite un nuevo token. La app Protectimus Smart OTP admite copia de seguridad en la nube, lo que permite a los usuarios restaurar sus tokens en un dispositivo nuevo sin intervenci\\u00f3n del administrador. Para otros casos de p\\u00e9rdida de token, puede emitirse y asignarse un token de reemplazo desde la consola de administraci\\u00f3n.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfEs compatible la MFA de Protectimus para Active Directory con entornos h\\u00edbridos de Azure AD (Entra ID)?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"S\\u00ed. Las organizaciones que ejecutan entornos h\\u00edbridos con Active Directory on-premise y Microsoft Entra ID pueden usar Protectimus para proteger el componente local de AD. La MFA de Protectimus tambi\\u00e9n puede integrarse con AD FS, lo que permite aplicar MFA a los flujos de autenticaci\\u00f3n que dependen de la federaci\\u00f3n de Active Directory.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfC\\u00f3mo se compara la MFA de Protectimus para Active Directory con las llaves FIDO2 y las passkeys?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"FIDO2 y las passkeys son m\\u00e9todos de autenticaci\\u00f3n resistentes al phishing dise\\u00f1ados principalmente para aplicaciones web modernas y servicios en la nube. Funcionan bien con aplicaciones federadas mediante ADFS y con escenarios de Microsoft Entra ID, pero tienen un soporte nativo limitado en los puntos de entrada heredados de Active Directory on-premise, incluidos Winlogon (sobre todo en versiones antiguas de Windows Server), RDP, las consultas LDAP y el acceso a AD por l\\u00ednea de comandos. Protectimus DSPA cubre todos estos puntos de manera uniforme con MFA basada en TOTP. En 2026, la mayor\\u00eda de las empresas adoptan un enfoque por capas: Protectimus DSPA para lograr una cobertura amplia de MFA en Active Directory en todos los servicios conectados a AD, y FIDO2\\\/passkeys de forma selectiva para las aplicaciones cr\\u00edticas en la nube accesibles a trav\\u00e9s de ADFS o Entra ID. Ambos enfoques se complementan, no compiten entre s\\u00ed.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfC\\u00f3mo protege la MFA de Protectimus contra los ataques pass-the-hash y pass-the-ticket?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Los ataques pass-the-hash (PtH) y pass-the-ticket (PtT) capturan tokens de autenticaci\\u00f3n o hashes de contrase\\u00f1a de la memoria y los reutilizan para autenticarse sin conocer la contrase\\u00f1a real. Protectimus DSPA eleva considerablemente la dificultad de estos ataques: como la contrase\\u00f1a de Active Directory se sustituye continuamente por una contrase\\u00f1a de un solo uso basada en tiempo (TOTP), un hash o ticket capturado solo es v\\u00e1lido durante la ventana del OTP vigente. Un atacante que captura un hash en el segundo 1 de una ventana de 30 segundos dispone, como mucho, de 29 segundos para usarlo antes de que la contrase\\u00f1a cambie y el hash quede invalidado. Esto reduce dr\\u00e1sticamente la explotabilidad pr\\u00e1ctica de estas t\\u00e9cnicas de ataque en comparaci\\u00f3n con entornos que solo usan contrase\\u00f1as est\\u00e1ticas.\"}},{\"@type\":\"Question\",\"name\":\"\\u00bfQu\\u00e9 marcos de cumplimiento ayuda a satisfacer la MFA de Protectimus para AD?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"La MFA de Protectimus para Active Directory aborda directamente los requisitos de MFA de varios marcos de cumplimiento. NIST SP 800-63B exige autenticaci\\u00f3n multifactor para los sistemas que manejan datos sensibles. PCI DSS v4.0 (requisito 8.4) exige MFA para todo acceso al entorno de datos de titulares de tarjetas. HIPAA requiere controles de acceso t\\u00e9cnicos para los sistemas que contienen informaci\\u00f3n sanitaria protegida. SOC 2 Type II suele exigir MFA como parte de los controles de acceso l\\u00f3gico evaluados durante la auditor\\u00eda. ISO 27001, en el Anexo A, control A.9.4, aborda el control de acceso a sistemas y aplicaciones. Protectimus es una soluci\\u00f3n certificada por OATH, lo que respalda las afirmaciones de cumplimiento en entornos que requieren est\\u00e1ndares de autenticaci\\u00f3n certificados.\"}}]}<\/script>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7534fb4 elementor-widget elementor-widget-html\" data-id=\"7534fb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"html.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<script type=\"application\/ld+json\">{\r\n  \"@context\": \"https:\/\/schema.org\",\r\n  \"@type\": \"HowTo\",\r\n  \"name\": \"How to Set Up MFA for Active Directory with Protectimus\",\r\n  \"description\": \"Step-by-step setup of multi-factor authentication for Active Directory using Protectimus: registration, payment plan activation, resource creation, and user\/token assignment. Full end-to-end deployment typically takes 1\u20132 days.\",\r\n  \"totalTime\": \"PT2H\",\r\n  \"estimatedCost\": {\r\n    \"@type\": \"MonetaryAmount\",\r\n    \"currency\": \"USD\",\r\n    \"value\": \"0\"\r\n  },\r\n  \"supply\": [\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Microsoft Active Directory or another LDAP-compatible directory\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Administrative access to the directory\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToSupply\",\r\n      \"name\": \"Server or private cloud meeting Protectimus On-Premise Platform requirements\"\r\n    }\r\n  ],\r\n  \"tool\": [\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus On-Premise Platform\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus DSPA component\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToTool\",\r\n      \"name\": \"Protectimus Smart OTP app or Protectimus Bot\"\r\n    }\r\n  ],\r\n  \"step\": [\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 1,\r\n      \"name\": \"Register with Protectimus\",\r\n      \"text\": \"Register with the Protectimus 2FA cloud service. Follow the registration link, fill out the registration form, and confirm your email address.\",\r\n      \"url\": \"https:\/\/www.protectimus.com\/mfa-for-active-directory\/#step-1\",\r\n      \"image\": \"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/1.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 2,\r\n      \"name\": \"Activate a payment plan\",\r\n      \"text\": \"To use the Protectimus SaaS platform and enable the API, activate a payment plan. Navigate to the Payment plans section of your account.\",\r\n      \"url\": \"https:\/\/www.protectimus.com\/mfa-for-active-directory\/#step-2\",\r\n      \"image\": \"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/2.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 3,\r\n      \"name\": \"Create a resource\",\r\n      \"text\": \"Resources are used to logically group users and OTP tokens. To create a resource, click Resources in your account menu on the left, then click Add resource at the top of the table.\",\r\n      \"url\": \"https:\/\/www.protectimus.com\/mfa-for-active-directory\/#step-3\",\r\n      \"image\": \"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/3.svg\"\r\n    },\r\n    {\r\n      \"@type\": \"HowToStep\",\r\n      \"position\": 4,\r\n      \"name\": \"Add users and OTP tokens\",\r\n      \"text\": \"Create users and OTP tokens, and assign them to the resource you created earlier. Service users will need logins in the format login@domain.com.\",\r\n      \"url\": \"https:\/\/www.protectimus.com\/mfa-for-active-directory\/#step-4\",\r\n      \"image\": \"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/07\/4.svg\"\r\n    }\r\n  ]\r\n}\r\n<\/script>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fe2c5b0 padded e-flex e-con-boxed e-con e-parent\" data-id=\"fe2c5b0\" data-element_type=\"container\" data-e-type=\"container\" id=\"conclusion\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e4ec716 e-con-full e-flex e-con e-child\" data-id=\"e4ec716\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-35746bf e-con-full e-flex e-con e-child\" data-id=\"35746bf\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-489bd70 e-con-full e-flex e-con e-child\" data-id=\"489bd70\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-10cf0aa elementor-widget elementor-widget-heading\" data-id=\"10cf0aa\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Conclusi\u00f3n: proteger Active Directory con MFA en 2026<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6c0eeb4 elementor-widget elementor-widget-text-editor\" data-id=\"6c0eeb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><span style=\"font-weight: 400;\">Active Directory es el componente m\u00e1s cr\u00edtico de la infraestructura de identidad en la mayor\u00eda de los entornos empresariales, y a la vez uno de los objetivos favoritos de los atacantes. Proteger AD solo con contrase\u00f1a ya no es una postura de seguridad viable en 2026, cuando el robo de credenciales, el phishing y ataques sofisticados como pass-the-hash y Kerberoasting forman parte del arsenal habitual de cualquier atacante. <\/span><\/p><p><span style=\"font-weight: 400;\">La autenticaci\u00f3n de dos factores de Protectimus para AD, impulsada por la tecnolog\u00eda DSPA (Dynamic Strong Password Authentication), resuelve los retos principales que hist\u00f3ricamente han dificultado el despliegue de 2FA en AD:<\/span><\/p><ul><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Una sola integraci\u00f3n, cobertura total:<\/b> <span style=\"font-weight: 400;\">una instalaci\u00f3n de DSPA protege autom\u00e1ticamente todos los servicios conectados a AD<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Sin agentes en el endpoint:<\/b> <span style=\"font-weight: 400;\">no hay que desplegar, mantener ni actualizar software en los equipos de los usuarios<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Implementaci\u00f3n flexible:<\/b> <span style=\"font-weight: 400;\">on-premise o nube privada para satisfacer cualquier requisito de cumplimiento<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Preparada para la gran empresa:<\/b> <span style=\"font-weight: 400;\">soporte multidominio, clustering, replicaci\u00f3n y pol\u00edticas basadas en grupos<\/span><\/li><li style=\"font-weight: 400;\" aria-level=\"1\"><b>Alineada con el cumplimiento normativo:<\/b> <span style=\"font-weight: 400;\">certificaci\u00f3n OATH, cobertura de PCI DSS, HIPAA, NIST e ISO 27001<\/span><\/li><\/ul><p><span style=\"font-weight: 400;\">Ya sea que proteja una pyme de 50 usuarios o una gran empresa con un bosque multidominio complejo de 50.000 usuarios, Protectimus ofrece un camino probado y pr\u00e1ctico para proteger Active Directory con MFA.<\/span><\/p><p><b>\u00bfListo para proteger su entorno de Active Directory?<\/b><\/p><p><span style=\"font-weight: 400;\"><a href=\"https:\/\/www.protectimus.com\/es\/contact-us\/\" target=\"_blank\" rel=\"noopener\">Solicite una demostraci\u00f3n gratuita<\/a> o contacte con Protectimus: nuestro equipo evaluar\u00e1 su entorno AD y le recomendar\u00e1 el enfoque de implementaci\u00f3n adecuado para su organizaci\u00f3n.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a3f81ec e-con-full contact-us-bg e-flex e-con e-child\" data-id=\"a3f81ec\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-fb3d121 elementor-widget elementor-widget-shortcode\" data-id=\"fb3d121\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\t\t<div data-elementor-type=\"container\" data-elementor-id=\"17554\" class=\"elementor elementor-17554 elementor-3585\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3a82e0d1 e-con-full e-flex e-con e-child\" data-id=\"3a82e0d1\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t<div class=\"elementor-element elementor-element-b4de036 elementor-widget elementor-widget-image\" data-id=\"b4de036\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"370\" height=\"370\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/05\/contact-seal.svg\" class=\"attachment-full size-full wp-image-17583\" alt=\"Send Us A Message icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1bc85d61 elementor-widget elementor-widget-heading\" data-id=\"1bc85d61\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h4 class=\"elementor-heading-title elementor-size-default\">Env\u00edenos un mensaje<\/h4>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cf09046 elementor-widget elementor-widget-shortcode\" data-id=\"cf09046\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"shortcode.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-shortcode\">\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f17553-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"17553\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/es\/wp-json\/wp\/v2\/pages\/18546#wpcf7-f17553-o1\" method=\"post\" class=\"wpcf7-form init\" aria-label=\"Contact form\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"17553\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.2\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f17553-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/>\n<\/fieldset>\n<div class=\"protectimus-form\">\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"uname\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Nombre\" value=\"\" type=\"text\" name=\"uname\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Correo electr\u00f3nico\" value=\"\" type=\"email\" name=\"email\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"subject\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Asunto\" value=\"\" type=\"text\" name=\"subject\" \/><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col\">\n <span class=\"wpcf7-form-control-wrap\" data-name=\"message\"><textarea cols=\"40\" rows=\"1\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Mensaje\" name=\"message\"><\/textarea><\/span>\n    <\/div>\n<\/div>\n\n<div class=\"row\">\n    <div class=\"col mb-2\">\n        <input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Enviar\" \/>\n    <\/div>\n<\/div>\n\n<\/div><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-584bd7e e-grid e-con-full equal-height equal-height-mob e-con e-child\" data-id=\"584bd7e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<a target=\"_blank\" target=\"_blank\" class=\"elementor-element elementor-element-3ef4592 e-con-full four-link e-flex e-con e-child\" data-id=\"3ef4592\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/service.protectimus.com\/en\/register\">\n\t\t\t\t<div class=\"elementor-element elementor-element-2278d47 eq-height elementor-widget elementor-widget-heading\" data-id=\"2278d47\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Iniciar prueba gratuita<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7af65ed elementor-widget elementor-widget-image\" data-id=\"7af65ed\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-11fd369 e-con-full four-link e-flex e-con e-child\" data-id=\"11fd369\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\" href=\"https:\/\/www.protectimus.com\/es\/contact-us\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-15127cf eq-height elementor-widget elementor-widget-heading\" data-id=\"15127cf\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Contactar con ventas<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-29ad51c elementor-widget elementor-widget-image\" data-id=\"29ad51c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-67ce6f7 e-con-full four-link e-flex e-con e-child\" data-id=\"67ce6f7\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/es\/pricing\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-39dc5c0 eq-height elementor-widget elementor-widget-heading\" data-id=\"39dc5c0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Ver precios<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b5c7dd4 elementor-widget elementor-widget-image\" data-id=\"b5c7dd4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t<a class=\"elementor-element elementor-element-6c78411 e-con-full four-link e-flex e-con e-child\" data-id=\"6c78411\" data-element_type=\"container\" data-e-type=\"container\" href=\"https:\/\/www.protectimus.com\/es\/guides\/saas-service\/\">\n\t\t\t\t<div class=\"elementor-element elementor-element-6358276 eq-height elementor-widget elementor-widget-heading\" data-id=\"6358276\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\">Ver gu\u00edas de integraci\u00f3n<\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-23eb343 elementor-widget elementor-widget-image\" data-id=\"23eb343\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"28\" height=\"26\" src=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/icon-arrow-big.svg\" class=\"attachment-full size-full wp-image-455\" alt=\"Arrow icon\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>MFA para Active Directory: gu\u00eda completa para proteger su entorno AD Active Directory es la base de la gesti\u00f3n de identidades en m\u00e1s del 90% de las empresas Fortune 1000, y tambi\u00e9n uno de los sistemas m\u00e1s atacados en el panorama actual de ciberseguridad. Una cuenta de AD comprometida da al atacante acceso a todo: [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"class_list":["post-18546","page","type-page","status-publish","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"google-site-verification\" content=\"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"PROTECTIMUS\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus\" \/>\n\t\t<meta property=\"og:description\" content=\"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-05-18T09:47:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-27T19:08:18+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/protectimus\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@Protectimus\" \/>\n\t\t<meta name=\"twitter:title\" content=\"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@Protectimus\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png\" \/>\n\t\t<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t\t<meta name=\"twitter:data1\" content=\"accounts@vipertop.com\" \/>\n\t\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t\t<meta name=\"twitter:data2\" content=\"30 minutes\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#listItem\",\"name\":\"MFA para Active Directory: proteja su AD con DSPA\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#listItem\",\"position\":2,\"name\":\"MFA para Active Directory: proteja su AD con DSPA\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#organization\",\"name\":\"Protectimus Ltd\",\"description\":\"Protectimus Ltd is a multi-factor authentication provider offering cloud and on-premise MFA software, hardware OTP tokens, authenticator applications, and ready-to-use integrations for enterprise infrastructure.\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"email\":\"sales@protectimus.com\",\"telephone\":\"+17867966664\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/wp-content\\\/uploads\\\/2024\\\/02\\\/logo-icon.svg\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#organizationLogo\",\"width\":72,\"height\":51,\"caption\":\"Protectimus logo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/protectimus\\\/\",\"https:\\\/\\\/x.com\\\/Protectimus\",\"https:\\\/\\\/www.youtube.com\\\/@ProtectimusSolutions\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/protectimus-solution-ltd\\\/\",\"https:\\\/\\\/github.com\\\/protectimus\",\"https:\\\/\\\/www.g2.com\\\/products\\\/protectimus\\\/reviews\",\"https:\\\/\\\/www.capterra.com\\\/p\\\/182993\\\/Protectimus\\\/\",\"https:\\\/\\\/www.gartner.com\\\/reviews\\\/product\\\/protectimus\",\"https:\\\/\\\/sourceforge.net\\\/software\\\/product\\\/Protectimus\\\/\",\"https:\\\/\\\/www.getapp.com\\\/security-software\\\/a\\\/protectimus\\\/\",\"https:\\\/\\\/www.softwareadvice.com\\\/product\\\/462406-Protectimus\\\/\",\"https:\\\/\\\/www.trustradius.com\\\/products\\\/protectimus\\\/reviews\",\"https:\\\/\\\/www.trustpilot.com\\\/review\\\/protectimus.com\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#webpage\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/\",\"name\":\"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus\",\"description\":\"Implement MFA for Active Directory in 1\\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \\u2014 no endpoint agents required.\",\"inLanguage\":\"es-ES\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/mfa-for-active-directory\\\/#breadcrumblist\"},\"datePublished\":\"2026-05-18T09:47:45+00:00\",\"dateModified\":\"2026-08-27T19:08:18+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/\",\"name\":\"PROTECTIMUS\",\"inLanguage\":\"es-ES\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.protectimus.com\\\/es\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus<\/title>\n\n","aioseo_head_json":{"title":"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus","description":"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.","canonical_url":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"6gzGBVioQ9rC9iYw9El7ERlDCLpc9c0ZqgJvbvqk0t4","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/#listItem","position":1,"name":"Home","item":"https:\/\/www.protectimus.com\/es\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#listItem","name":"MFA para Active Directory: proteja su AD con DSPA"}},{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#listItem","position":2,"name":"MFA para Active Directory: proteja su AD con DSPA","previousItem":{"@type":"ListItem","@id":"https:\/\/www.protectimus.com\/es\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/www.protectimus.com\/es\/#organization","name":"Protectimus Ltd","description":"Protectimus Ltd is a multi-factor authentication provider offering cloud and on-premise MFA software, hardware OTP tokens, authenticator applications, and ready-to-use integrations for enterprise infrastructure.","url":"https:\/\/www.protectimus.com\/es\/","email":"sales@protectimus.com","telephone":"+17867966664","logo":{"@type":"ImageObject","url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/logo-icon.svg","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#organizationLogo","width":72,"height":51,"caption":"Protectimus logo"},"image":{"@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/protectimus\/","https:\/\/x.com\/Protectimus","https:\/\/www.youtube.com\/@ProtectimusSolutions","https:\/\/www.linkedin.com\/company\/protectimus-solution-ltd\/","https:\/\/github.com\/protectimus","https:\/\/www.g2.com\/products\/protectimus\/reviews","https:\/\/www.capterra.com\/p\/182993\/Protectimus\/","https:\/\/www.gartner.com\/reviews\/product\/protectimus","https:\/\/sourceforge.net\/software\/product\/Protectimus\/","https:\/\/www.getapp.com\/security-software\/a\/protectimus\/","https:\/\/www.softwareadvice.com\/product\/462406-Protectimus\/","https:\/\/www.trustradius.com\/products\/protectimus\/reviews","https:\/\/www.trustpilot.com\/review\/protectimus.com"]},{"@type":"WebPage","@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#webpage","url":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/","name":"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus","description":"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.","inLanguage":"es-ES","isPartOf":{"@id":"https:\/\/www.protectimus.com\/es\/#website"},"breadcrumb":{"@id":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/#breadcrumblist"},"datePublished":"2026-05-18T09:47:45+00:00","dateModified":"2026-08-27T19:08:18+00:00"},{"@type":"WebSite","@id":"https:\/\/www.protectimus.com\/es\/#website","url":"https:\/\/www.protectimus.com\/es\/","name":"PROTECTIMUS","inLanguage":"es-ES","publisher":{"@id":"https:\/\/www.protectimus.com\/es\/#organization"}}]},"og:locale":"es_ES","og:site_name":"PROTECTIMUS","og:type":"article","og:title":"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus","og:description":"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.","og:url":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/","og:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","og:image:secure_url":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","article:published_time":"2026-05-18T09:47:45+00:00","article:modified_time":"2026-08-27T19:08:18+00:00","article:publisher":"https:\/\/www.facebook.com\/protectimus\/","twitter:card":"summary_large_image","twitter:site":"@Protectimus","twitter:title":"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus","twitter:description":"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required.","twitter:creator":"@Protectimus","twitter:image":"https:\/\/www.protectimus.com\/wp-content\/uploads\/2024\/02\/protectimus-logo.png","twitter:label1":"Written by","twitter:data1":"accounts@vipertop.com","twitter:label2":"Est. reading time","twitter:data2":"30 minutes"},"aioseo_meta_data":{"post_id":"18546","title":"MFA for Active Directory: Agentless AD MFA Guide (2026) | Protectimus","description":"Implement MFA for Active Directory in 1\u20132 days. Protectimus DSPA secures Winlogon, RDP, OWA, ADFS, and LDAP with one integration \u2014 no endpoint agents required. ","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-09-08 08:37:29","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":"0","open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-24 19:41:03","updated":"2026-09-08 08:37:29","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.protectimus.com\/es\/\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tMFA para Active Directory: proteja su AD con DSPA\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.protectimus.com\/es\/"},{"label":"MFA para Active Directory: proteja su AD con DSPA","link":"https:\/\/www.protectimus.com\/es\/mfa-for-active-directory\/"}],"_links":{"self":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18546","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/comments?post=18546"}],"version-history":[{"count":3,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18546\/revisions"}],"predecessor-version":[{"id":18604,"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/pages\/18546\/revisions\/18604"}],"wp:attachment":[{"href":"https:\/\/www.protectimus.com\/es\/wp-json\/wp\/v2\/media?parent=18546"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}