Account configuration #77
-
Hi! |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 3 replies
-
Hi, good question! Home users have MSA and that's enough, but real security is when there is no local admin and identities are managed using Entra ID. It can allow for multi-factor unlock, so you can enforce PIN + Face or PIN + Fingerprint to unlock Windows, top security stuff. All accounts should be connected to Microsoft accounts online, be password-less, use MFA with Authenticator app, use OneDrive for backup/restore capability etc. Regardless of how many accounts you have, you only need to run it once as administrator to make system-wide changes, then for each standard user you can run the script without elevation so non-admin category can apply to the standard account, but even if you don't do this the system-wide changes are enough 🙂 I made some changes to the readme |
Beta Was this translation helpful? Give feedback.
-
Thanks! |
Beta Was this translation helpful? Give feedback.
Hi, good question!
Either Microsoft account or AAD/Entra ID
Home users have MSA and that's enough, but real security is when there is no local admin and identities are managed using Entra ID. It can allow for multi-factor unlock, so you can enforce PIN + Face or PIN + Fingerprint to unlock Windows, top security stuff.
All accounts should be connected to Microsoft accounts online, be password-less, use MFA with Authenticator app, use OneDrive for backup/restore capability etc.
Regardless of how many accounts you have, you only need to run it once as administrator to make system-wide changes, then for each standard user you can run the script without elevation so non-admin category can appl…