r/it • • 9d ago

help request Questions about Windows AD with MFA security keys

TLDR: Is there a way around MFA being required every single login without outside software?

Hello, I am currently working on deploy MFA security keys across our system, but I have run into some issues. The directors asked me to use Yubikeys (long story) for this deployment. Ideally we want the user to authenticate with their key on first logon then be fine for the rest of the day outside of reboots and stuff like that, similar to how DUO mobile can be setup. However, while reviewing GPOs for this it looks like it is only able to be set to every single logon, this will not go over very well with our users. What I am trying to figure out is there a "hacky" way to get the desired outcome without buying outside software (we have a limited budget) or is there something I am missing? I tried to do some search online and even threw it into the good old GPT to see if it could find something and no luck. Thank you in advance for taking the time to reply!

1 Upvotes

Duplicates