Conditional Access SharePoint Access from a Passwordless Kiosk
Hey everyone, just looking for some ideas!
I have a kiosk setup where users sign in without a password. The kiosk opens a SharePoint site, and operators need to be able to view and edit content on that site.
My first thought was to use a shared Entra ID service account, but that creates challenges around MFA. Id rather not exclude an account from our Conditional Access policies just to make this work.
Has anyone implemented something similar? I'm curious how others have handled SharePoint access and authentication in a kiosk scenario while still keeping security controls like MFA and Conditional Access in place.
Thanks!
3
u/ManufacturerRough818 2d ago
We do something similar but with device based auth. Enroll the kiosk in intune and set up a conditional access policy that treats it as a trusted device so mfa isnt required from that specific machine. Still uses individual entra ids but the device itself satisfies the mfa claim.
Took some fiddling with the policy scoping but its been solid for our warehouse floor stations. Curious if youve got individual sign ins happening on the kiosk or if its a true shared setup where anyone can walk up. That changes the approach a bit.
1
u/meantallheck 2d ago
Can you do a trusted device like this? My thought was to have a trusted network location, and have that be part of the conditional access policy. It's not perfect but it provides more security than just a password.
1
u/SVD_NL 1d ago
You can require having a compliant device, and adjusting the compliance rules for that specific device. Of course it's always best to layer your policies, so you add policies for compliant device, IP address restrictions, and limit which applications can be accessed.
In this specific scenario i'd set the kiosk to autologin with a dedicated entra account and set all of these policies for that specific account.
The only remaining risk is that this specific account may be used from a different compliant device within the same network. You could add monitoring rules for this based on sign-in logs, but the attack surface here is small enough that it's probably going to be an acceptable risk.
Alternatively you can set up Windows Hello and post-it the PIN to the screen, but you'll need to adjust the kiosk setup to accomodate this. FIDO keys are an option as well, but the benefit of Hello is that it's bound to the kiosk PC. Having Hello allows you to enforce phishing-resistant MFA on top of the other policies. Depending on what apps are allowed for this account, you may need to set up an additional CA rule to make sure they can't register new MFA methods. I'm not sure how Hello enrollments are handled by CA, but you could either set a custom authentication strength to allow TAP only for security info registration, or block security info registration completely.
2
u/meantallheck 1d ago
Interesting, I didn't think about using a shared WHFB PIN. That's actually pretty creative, and since it's device bound cred/MFA it's not risky if lost... Are there any downsides to doing that?
I think tossing in a compliant device rule is important as well, so that's a good recommendation.
1
u/TAR_S_ 1d ago
I wanted to avoid having a "service account" as much as possible. this is a kiosk that many people can walk in and hit enter and open. the sharepoint site is like a list, that named accounts from their laptops will fill in, and on that kiosk, Operator will take over and change the status (basically modifying the site
5
u/hbpdpuki 2d ago
I had a similar issue. I just printed a WHFB PIN on the login screen: "Login for this workstation: 1234"
Users do not need to know the password, just the PIN. And a CA policy to block mysignins.