Welcome to Microsoft Q&A Forum!
In an RD Gateway and NPS (Azure MFA extension) scenario, the MFA timeout behavior can be confusing because it is not controlled by a single setting.
The Azure MFA NPS extension has a built-in timeout of approximately 20 seconds, which cannot be changed via registry or configuration.
- If the MFA approval (push/OTP) is not completed within this time, the request is automatically rejected
- There is no supported registry key or setting to extend this internal timeout
Reference: RADIUS and Azure MFA Extension, how to extend 20 seconds timeout ? - Microsoft Q&A
Based on your description, updating registry keys did not resolve the issue, which is expected behavior. This is because the MFA timeout is hardcoded in the Azure MFA extension, and only the RADIUS/network timeout values in the authentication chain are configurable.
Although the MFA timeout itself cannot be extended, you should align timeout settings across all RADIUS components:
1. NPS (Remote RADIUS Server Group)
- Path: Server Manager > Tools > Network Policy Server → RADIUS Clients and Servers → Remote RADIUS Server Groups → Properties → Load Balancing
- Increase “Number of seconds without response before request is dropped” (for example, 60 seconds)
This ensures NPS itself doesn’t give up too early.
Reference: Increase timeout settings MFA on NPS server - Microsoft Q&A
2. RDS Gateway Timeout Settings
- RD Gateway does not control the Azure MFA timeout itself
- Its session and authentication timeout settings are separate and do not affect the MFA push duration
- These values (including idle/session timeout via GPO) are unrelated to MFA timing
3. Other RADIUS clients / network devices
- Any upstream device (RD Gateway, VPN, firewall, load balancer) must have a timeout equal to or greater than the NPS timeout
- If any component has a shorter timeout, the authentication request may be dropped before MFA completes
I hope this information is helpful and thank you for choosing Microsoft Q&A to raise your concern.
Note: This answer has been translated using a translation tool. Please note that there may be grammatical or semantic errors. Thank you for your understanding. If there is any unclear part of the answer, please leave it in the comments and we will get back to you as soon as possible.