Solutions for MFA on Windows Login
Posted by Beznia@reddit | sysadmin | View on Reddit | 85 comments
Hey guys,
One of my current tasks is scoping out tools which would allow us to implement configuring all of our laptops to require Microsoft Authenticator when users log into their machine.
The goal here is to utilize the existing Authenticator that our users have tied to their Entra accounts. Microsoft doesn't seem to support this with Windows Hello for Business and we have a hard No from our legal team to use any sort of biometric authentication, which is the reason for the Authenticator requirement.
In my research, I see ManageEngine seems to support this with ADSelfService Plus which is what I am demoing now, but I was curious if anyone else has implemented this sort of solution as well with any other service provider. I have also looked at Duo but Duo seems to only support using their authenticator rather than integrating with our Entra ID.
We're fully aware that if a user does not have their cellphone that they cannot sign into their computer and this is something the business is fine with.
An important caveat in our case is our machines are Hybrid so users log in with AD credentials. We are in the process of moving towards Cloud-only later in the year but we have approximately 3,000 users and that will be a larger project in itself.
85 Comments
William_NAtty@reddit
Clarence_Mertens@reddit
maryteiss@reddit
Upper_Caterpillar_96@reddit
Lbrown1371@reddit
jaank80@reddit
Codename_Sidewinder@reddit
Asleep_Spray274@reddit
Professional-Heat690@reddit
TheCyberThor@reddit
ReputationNo8889@reddit
JwCS8pjrh3QBWfL@reddit
gamebrigada@reddit
JwCS8pjrh3QBWfL@reddit
gamebrigada@reddit
Reedy_Whisper_45@reddit
LaxVolt@reddit
raip@reddit
LaxVolt@reddit
Beznia@reddit (OP)
itsTeabow@reddit
Khue@reddit
Beznia@reddit (OP)
cvc75@reddit
ITguyBass@reddit
Patient-Stuff-2155@reddit
gamebrigada@reddit
Lancegoodheart@reddit
tailorgayng@reddit
Beznia@reddit (OP)
Darkhexical@reddit
Darkhexical@reddit
Darkhexical@reddit
TechIncarnate4@reddit
ExceptionEX@reddit
raip@reddit
ExceptionEX@reddit
TechIncarnate4@reddit
CharacterLimitHasBee@reddit
oddball667@reddit
chum-guzzling-shark@reddit
sarosan@reddit
Sprocket45@reddit
AfterEagle@reddit
AlexHuntKenny@reddit
Lord_Saren@reddit
Routine_Brush6877@reddit
TeensyTinyPanda@reddit
oddball667@reddit
TeensyTinyPanda@reddit
daelsant@reddit
dadoftheclan@reddit
the_doughboy@reddit
secret_configuration@reddit
cisco@reddit
sidEaNspAn@reddit
Asleep_Spray274@reddit
pc_load_letter_in_SD@reddit
doofesohr@reddit
pc_load_letter_in_SD@reddit
AutisticToasterBath@reddit
AppIdentityGuy@reddit
Secret_Account07@reddit
Beznia@reddit (OP)
gwildor@reddit
Beznia@reddit (OP)
gwildor@reddit
Beznia@reddit (OP)
gwildor@reddit
Beznia@reddit (OP)
gwildor@reddit
Sinsilenc@reddit
ntrlsur@reddit
Beznia@reddit (OP)
buck-futter@reddit
ExceptionEX@reddit
ExceptionEX@reddit
TeensyTinyPanda@reddit
akdigitalism@reddit
TerrorToadx@reddit
masterne0@reddit
kubrador@reddit
saxmaster896@reddit
mautobu@reddit
ITguyBass@reddit