jblackburnHWGA Posted December 16, 2020 Posted December 16, 2020 I'm working on my current build of an Azure AD only device that completely runs from Endpoint. I'm just trying to figure out how to enable the fingerprint reader using hello for business I've enabled it but when it goes though to setup the pin it wants a to setup an additional verification method Any advice for an education setup? I can't set the windows hello to staff only I've noticed which isn't that bad as i can disable the settings menu for kids. From a staff point of view what do you advise? Use a school phone where possible or use a personal phone as the security verification As there an alternative way around this? We currently have an on prem setup but are moving serverless. The domain is federated and uses AAD to sync with azure.
psydii Posted December 16, 2020 Posted December 16, 2020 We're gradually getting all staff personal mobiles into system for password resets. Politically difficult to mandate. We are going via the "user risk policy " and "sign-in risk policy" mechanisms in Azure (hey, Azure blocked your sign in due to suspicious activity - please prove its you!) Staff at that point are usually pretty willing to have us copy their personal mobile from SIMS into Azure AD. We've recently had to extend this to kids too. For this we contact parents for permission to add either their child's mobile or their mobile for the purposes of account recovery. We do have most of these on record already in SIMS, but no-one has the stomach for justifying the bulk import with all the stakeholders. Once we hit a critical mass we'll revisit engaging staff and parent/students to complete bulk enrolment.
jblackburnHWGA Posted December 16, 2020 Author Posted December 16, 2020 so there's no work around. its a land line number, app or mobile for text only. I'm assuming you can clear the pin for the staff member or remove the associated number for the account
psydii Posted December 16, 2020 Posted December 16, 2020 I really can't say. I was commenting from a 'using personal mobile numbers as second factor authentication' perspective. I would have thought that a remote wipe of an autopilot enrolled device should reset Windows Hello keys in the TPM - but this sits outside area of expertise.
jblackburnHWGA Posted December 16, 2020 Author Posted December 16, 2020 Thanks Psydii. I'll give it a test with one of my teachers who I'm using to test the Azure joined devices
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now