Hello Mohammed,
the IBM Multi-Factor Authentication solution allows for a RACF UID to use an Active Directory Account for z/OS authentication.
The RACF-UID is mapped to a AD Account (via TAGS in an enrollment for a UID) and the AD PW is used additional or instead of
the RACF-PW. zMFA Faktor used is LDAP via "simple bind" to AD.
More details you can find here: https://www.ibm.com/docs/en/SSNR6Z_2.2.0/pdf/azfi100_v2r2.pdf
See Chapter 20. Configuring LDAP
Best regards Guenter
------------------------------
Günter Weber
------------------------------