Forum Discussion

Deleted's avatar
Deleted
Jul 20, 2018

How to logon with Azure AD credentials on a Windows 10 device with MFA enabled

Hi together,

 

maybe one of you have got the same requirements and run into the same problem.

 

situation:

Windows 10 enterprise or windows 10 s

Microsoft Intune Cloud (EMS)

Microsoft Multi-Factor Authentication (MFA) on-premises handled by ADFS (internal no mfa, external (wap) force mfa)

Company Wifi protected with certificates

Credentials from Azure AD

 

Problem 1:

As far as I have found, Intune is only able to deploy user certificates (SCEP profile) for wifi on windows devices. This causes us that you initially can only logon with your azure ad credentials to a windows machine if you have plugged in the company network or you have a public wifi connection with no authentication, so that you can connect to a wifi on the logon screen. Does anyone managed to deploy client certificates with Intune?

 

Problem 2:

As mentioned above we use MFA on-premises and it’s handled by adfs. If a user authenticates from external (over wap) we force mfa on adfs side. This is fine for web applications and other apps but it seems that windows logon cannot handle mfa request and therefore it fails. Does anyone know if this can be achieved somehow that this scenario works? Could this be handled by conditional access?

 

 

The goal should be that we can use a windows 10 enterprise or windows 10 s device with azure ad credentials which is authenticated to our company wifi network at logon screen already and that we can use multi-factor authentication somehow.

Thanks in advance for any input!

3 Replies

Resources