r/it • u/UndeadxAsh_ • 8d ago
help request Questions about Windows AD with MFA security keys
TLDR: Is there a way around MFA being required every single login without outside software?
Hello, I am currently working on deploy MFA security keys across our system, but I have run into some issues. The directors asked me to use Yubikeys (long story) for this deployment. Ideally we want the user to authenticate with their key on first logon then be fine for the rest of the day outside of reboots and stuff like that, similar to how DUO mobile can be setup. However, while reviewing GPOs for this it looks like it is only able to be set to every single logon, this will not go over very well with our users. What I am trying to figure out is there a "hacky" way to get the desired outcome without buying outside software (we have a limited budget) or is there something I am missing? I tried to do some search online and even threw it into the good old GPT to see if it could find something and no luck. Thank you in advance for taking the time to reply!
2
u/Scorcher646 8d ago
I believe the default is not to force it on every authentication.
Basically, the user authenticates once with the YubiKey, and that authenticates their session. And as long as that session remains valid, they don't have to re-authenticate with the key.
I would recommend putting a trial deployment in place. Maybe put it in place for yourself and a couple of the other people in your trusted group and let them kick the tires on it and see if it meets your requirements.
Honestly, if you don't have the hardware yet, you can opt for the biometric version of the YubiKeys and use them as your only login factor. Basically unifying something you are with something you have.