Jump to content

Recommended Posts

Posted

I am trying to use the online method of Get-WindowsAutoPilotInfo (using the -Online) switch, but current policy dictates that all global admin users have security key only as the only method for 2FA, which I would agree is good security practice. However 2FA prompts initiated by powershell commands currently don't always support FIDO2 MFA support.

We are using AutoPilotOOBE module at Windows OOBE/Setup, however I have tried running Get-WindowsAutoPilotInfo.ps1 -Online within a running version of Windows 10 to get the Sign in Prompt, but get stuck at the 2FA part of the process with a window that continually loops at "Working".

 

Is anyone else in the same situation, and how have you implemented a work-around? I can only think of having a single named location (the office at work) to possibly allow a second method for 2FA (such as Authenticator App) for directory admins only for Intune/Autopilot App.

 

Looking for some guidance here, as using the CSV method is a little slow...

 

Cheers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...