Event details
Do you manage Windows endpoints in Intune? Do you have questions that extend beyond configuration and involve ensuring security, compliance, and a seamless user experience on Windows? Join this Ask M...
Char_Cheesman
Updated Dec 27, 2024
BrandonBrown
Mar 20, 2024Brass Contributor
Our organization is trying out the passwordless capability as part of the Authentication Policy CSP, but we are struggling with the some of the functionality as currently designed and documented: https://learn.microsoft.com/en-us/windows/security/identity-protection/passwordless-experience/#in-session-authentication-experiences
To keep this short: What is the reasoning behind forcing in-session authentication to the built-in local Administrator account and not allowing the opportunity to provide another account with local administrator access to authenticate? LAPS is great and it works but is hard to track down to who actually performed that action, aka retrieved the LAPS password from Entra, and EPM requires additional configuration, doesn't currently check all of the boxes, and most importantly, comes at an additional cost.
- Char_CheesmanMar 20, 2024Bronze Contributor
Thanks for participating in today's session of AMA: Windows management with Intune! For reference, the panel covered this topic at around 36:45.
- BrandonBrownMar 20, 2024Brass ContributorThank you, Charlize. Still hoping the team can provide some insight on the in-session authentication when turning on the passwordless experience with the Authentication Policy CSP 🙂