Is there a way to use Microsoft Authenticator MFA for domain users signing in a Windows 10 (Domain, Intune) device?

Panagiotis Glykos 25 Reputation points
2023-02-17T11:16:34.67+00:00

Hello all,

Is there a way to use Microsoft Authenticator MFA for domain users signing in a Windows 10 (Domain, Intune) device?

We are working on the scenario where a (AD - Azure AD) user can sign on a corporate Windows 10 device, using MFA with Microsoft Authenticator (OTP or Push Notification) besides its account password.

Thank you!

Microsoft Security Microsoft Entra Microsoft Entra ID
Microsoft Security Microsoft Authenticator
{count} vote

Accepted answer
  1. Sandeep G-MSFT 20,906 Reputation points Microsoft Employee Moderator
    2023-02-27T08:03:16.7633333+00:00

    @Panagiotis Glykos

    Microsoft does not allow any Azure MFA at the time of Windows login. A normal MFA which is supported by MS is Windows Hello or Pin.
    However, if you must find a way with authenticator App during Windows Login, you can try some 3rd parties that integrate this functionality with their 3rd party tools.
    Using 3rd parties for this is solely up to you and MS does not support/recommend them.

    As a informational piece, you can look at : https://james-rankin.com/articles/adding-microsoft-authenticator-mfa-to-windows-logon-using-manageengine-ad-self-service-plus/ to understand how other people might be using it.
    [The link is a 3rd party link and is used for knowledge purpose only, MS is not responsible for any information shared in that.]

    If you users want MFA to be prompted while taking RDP to hybrid Azure AD joined devices then, there are few other routes we can take a look if that suits your need. Like NPS extension with Azure MFA. Also, RDS infra with Azure MFA.

    https://learn.microsoft.com/azure/active-directory/authentication/howto-mfa-nps-extension-rdg
    https://learn.microsoft.com/azure/active-directory/authentication/howto-mfa-nps-extension

    If you are still looking to implement MFA while Windows login screen then you can submit the feedback directly in Azure feedback portal. These are directly monitored by our PM's.

    https://feedback.azure.com/d365community/idea/e2f93898-9b48-ed11-a81b-000d3a04ded5

    There is already feedback which is given in Azure feedback portal. You can upvote on the same.

    Let me know if you have any further questions.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.