Solutions for MFA on Windows Login

Posted by Beznia@reddit | sysadmin | View on Reddit | 85 comments

Hey guys, One of my current tasks is scoping out tools which would allow us to implement configuring all of our laptops to require Microsoft Authenticator when users log into their machine. The goal here is to utilize the existing Authenticator that our users have tied to their Entra accounts. Microsoft doesn't seem to support this with Windows Hello for Business and we have a hard No from our legal team to use any sort of biometric authentication, which is the reason for the Authenticator requirement. In my research, I see ManageEngine seems to support this with ADSelfService Plus which is what I am demoing now, but I was curious if anyone else has implemented this sort of solution as well with any other service provider. I have also looked at Duo but Duo seems to only support using their authenticator rather than integrating with our Entra ID. We're fully aware that if a user does not have their cellphone that they cannot sign into their computer and this is something the business is fine with. An important caveat in our case is our machines are Hybrid so users log in with AD credentials. We are in the process of moving towards Cloud-only later in the year but we have approximately 3,000 users and that will be a larger project in itself.