Is anyone doing 2FA on desktops and laptops?<\/p>\n
What do you use?<\/p>\n
Duo looks like it needs every laptop to have internet access at logon time so doesn’t appear practical.<\/p>\n
Like the look/price of Yubikey but not sure about the software infrastructure required on top of AD.<\/p>","upvoteCount":7,"answerCount":10,"datePublished":"2018-01-26T12:52:54.000Z","author":{"@type":"Person","name":"servermonkey8064","url":"https://community.spiceworks.com/u/servermonkey8064"},"suggestedAnswer":[{"@type":"Answer","text":"
Is anyone doing 2FA on desktops and laptops?<\/p>\n
What do you use?<\/p>\n
Duo looks like it needs every laptop to have internet access at logon time so doesn’t appear practical.<\/p>\n
Like the look/price of Yubikey but not sure about the software infrastructure required on top of AD.<\/p>","upvoteCount":7,"datePublished":"2018-01-26T12:52:54.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/1","author":{"@type":"Person","name":"servermonkey8064","url":"https://community.spiceworks.com/u/servermonkey8064"}},{"@type":"Answer","text":"
Why not SmartCard with PIN?<\/p>","upvoteCount":0,"datePublished":"2018-01-26T13:13:28.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/2","author":{"@type":"Person","name":"bucko","url":"https://community.spiceworks.com/u/bucko"}},{"@type":"Answer","text":"
Look into authlite. Uses yubikeys and builds on top of AD.<\/p>\n
https://www.authlite.com/<\/a><\/p>","upvoteCount":1,"datePublished":"2018-01-26T13:31:37.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/3","author":{"@type":"Person","name":"seani","url":"https://community.spiceworks.com/u/seani"}},{"@type":"Answer","text":" Depending on your infrastructure, Intel makes an add-in product called Authenticate<\/a> that can work with hardened points on the system and also with Microsoft Hello to offer multi-factor options such as fingerprint (hardened where possible), facial recognition (via Hello), PIN (hardened), AMT location (hardened), virtual smart card (hardened), and a couple of other factors. The nice thing is that it’s free, though it does require a TPM and vPro<\/a> in order to harden factors. If you’ve deployed vPro systems, then it’s essentially gift with purchase.<\/p>","upvoteCount":0,"datePublished":"2018-01-26T14:09:13.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/4","author":{"@type":"Person","name":"davidvaldez4","url":"https://community.spiceworks.com/u/davidvaldez4"}},{"@type":"Answer","text":" We use duo on all our laptops, and yes they do have to have a connection before they can log on. Since they have to be on our vpn to talk to anything but duo and vpn though it’s not like they’d be getting used without a connection and you can setup a connection from login screen.<\/p>","upvoteCount":1,"datePublished":"2018-01-26T14:16:36.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/5","author":{"@type":"Person","name":"drewlubken0647","url":"https://community.spiceworks.com/u/drewlubken0647"}},{"@type":"Answer","text":" I’m trialing Duo now as well, and this (and the default fail open) was a sticking point for me. They told me it should work if you use a Yubikey. I briefly tried that and wasn’t able to get it to work, but have a call scheduled with them for next week.<\/p>\n Otherwise, I really like it - I’ve been able to get it working on Windows and Linux, and they support everything else I wanted.<\/p>","upvoteCount":0,"datePublished":"2018-01-26T18:04:38.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/6","author":{"@type":"Person","name":"bryandoe","url":"https://community.spiceworks.com/u/bryandoe"}},{"@type":"Answer","text":" No - if I did most of my users wouldnt be starting work until Wednesday morning<\/p>\n 50% forget their AD passwords over the weekend<\/p>\n<\/li>\n 50-75% forget their encryption key or phone IT to say they have a ‘blue screen’ at login<\/p>\n<\/li>\n 25% claim not to have Chrome installed<\/p>\n<\/li>\n 100% moan about 2FA for 365 and VPN<\/p>\n<\/li>\n<\/ul>","upvoteCount":2,"datePublished":"2018-01-26T20:11:55.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/7","author":{"@type":"Person","name":"tobywells","url":"https://community.spiceworks.com/u/tobywells"}},{"@type":"Answer","text":" We had it at my previous employer with Duo. You can set it to not bypass the login if there is no Internet otherwise it will be as you state without Internet it is bypassed.<\/p>","upvoteCount":0,"datePublished":"2018-01-26T20:53:53.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/8","author":{"@type":"Person","name":"dbeato","url":"https://community.spiceworks.com/u/dbeato"}},{"@type":"Answer","text":" The problem is MFA is a second-class citizen in Windows AD environments. It’s the nature of how it handles SSO. You can deploy MFA for interactive logins (RDP and local), but other services, such as SMB/445, WMI/135, HTTP, etc can still be logged into without MFA, and those are the ones the hackers really like to go after.<\/p>\n Such has been my experience, anyway. Maybe things are better since the last time I looked into it.<\/p>","upvoteCount":0,"datePublished":"2018-01-30T16:46:31.000Z","url":"https://community.spiceworks.com/t/2fa-for-desktops-and-laptops/631122/9","author":{"@type":"Person","name":"travisfriesen","url":"https://community.spiceworks.com/u/travisfriesen"}},{"@type":"Answer","text":"\n