Forum Discussion

Mirza Dedic's avatar
Mirza Dedic
Copper Contributor
Oct 13, 2021

Request for Windows GINA/CP logon agent for Microsoft Authenticator (MFA)?

Hi,

 

We have domain joined Windows 10 computers, synced to Azure AD (hybrid join). In Azure we have conditional access MFA. Devices are managed by MECM/Intune.

 

How can we enable MFA prompt during Windows login? I know that Windows Hello and FIDO2 exists however this route has a lot of overhead compared to having a GINA/CP logon agent.

 

This isn't anything new or ground breaking, we want to enable Authenticator MFA prompt when users login with their username/password to the workstation.

 

Duo and Okta has this feature for many years now. It has been requested and suggested on the now defunct. Azure feedback site for awhile.

 

Is there anything in the works to have something like this? Not everyone in the enterprise wants to roll Windows Hello or FIDO2.

 

https://docs.microsoft.com/en-us/answers/questions/43810/windows-10-mfa-at-login-on-azure-ad.html 

https://www.reddit.com/r/sysadmin/comments/dbt3kh/how_can_we_enable_mfa_on_a_windows_10_login/

 

9 Replies

Resources