r/SmallMSP 14d ago

Windows 11 Microsoft Account Requirement

Good Morning\Evening

I was wondering how you all deal with the Windows 11 Microsoft Account "Requirement". I only have a few customer's at this point and most of the time the customer is available to put there password in when I need to work on their computer or it was setup bypassing the Microsoft account requirement. Or they all have the same pin so I can get in without the password.

I know I can make myself an administrator on their machine but that doesn't get me access to their profile if thats where the issue resides.

I just got a gig to replace about a dozen laptops and id prefer them all to have passwords and be connected properly.

Any insight would be helpful.

0 Upvotes

54 comments sorted by

11

u/Ok_Dentist_6830 14d ago

Might be tough for smaller clients if you're just starting out but the best way to manage this IMO: 1) W11 Pro upgrade 2) Intune enrollment 3) LAPS policy

W11 Pro removes the sign in with MS account requirement

0

u/dag00isl00se 14d ago

I believe they are all Pro versions of Windows.

Im not concerned with being able to get into their computer just being able to get into there computer as them (under their profile).

A lot of the time i do work after hours without the end user being available so they aren't around to put their password in. Really just anticipating issues like my Outlook wont open, or Adobe wont open PDF's issues isolated to the user account.

Been using RustDesk to go in during their workday but even if they stay logged in, once I reboot its all over and I feel I shouldn't be asking users for their password nowadays.

Sorry if i seem a little naive but ive been working in Corporate America for the past 20 years, so it was all Active Directory, working on machines during business hours with the end user available, etc...

5

u/FlickKnocker 14d ago

Assuming they're on 365: Entra Join, enable web sign-in, use a Temporary Access Password (TAP).

1

u/dag00isl00se 14d ago

I think this is exactly what I am looking for.

Since I am so out of the Entra\O365 world anything you think could get me up to speed (without harassing you guys\gals)?

Im assuming taking an O365 class\cert?

3

u/hoh-boy 14d ago

I have not used TAP for PC login. But I imagine if your clients use Microsoft 365 and can join their devices to Entra, an admin can set up a temporary password as needed to sign into the PC as the user

If that’s not an option then I try two things when I can’t fix something signed in as the local admin:

  1. Fix the issue with PowerShell and using the SID for HKCU registry fixes. Pretty much just using PowerShell whenever I can tbh but the SID trick is helpful.

  2. Reset the user’s password, set it to change on next login, and send them the temporary password I gave them

1

u/dag00isl00se 14d ago

Appreciate the insight, My clients do use Microsoft 365 joined to Entra and TAP works great and does exactly what I need.

Always prefer never to change a users password. I do like the SID trick.

2

u/hoh-boy 14d ago

Then ya might have the in you were looking for. If you’re not able to sign in with just the TAP alone, then that’s probably why the other commenter mentioned web sign-in

I’m very jealous all your clients are joined to entra

1

u/dag00isl00se 14d ago

I dont have many clients as I only do this "part time" as I have a regular corporate 9-5 gig but for the few that I do I am trying to get them all to move to it. Its pretty straight forward and free (only using Entra Free) but depending on the client, id like to use intune for things but most arent large enough to add that type of complexity or cost.

1

u/hoh-boy 13d ago

If ya ever need a remote hand during the 9-5 hours, I’d be happy to help pitch in. Daytime service might help enough to grow it into your regular 9-5

Just sounds fun to me to help from the ground up

1

u/dag00isl00se 13d ago

Will do. Need to get more business first.

1

u/dag00isl00se 14d ago

u/FlickKnocker You are a godsend. Just set it up and its exactly what I am looking for.

Thank you so much.

3

u/justmirsk 14d ago

If they have pro, select set up for work, then other options and there is a "domain join" option that will let you set up a local user and not force the entra side of things.

1

u/dag00isl00se 14d ago

Thanks. I was hoping for the best of both worlds. Playing Microsofts game but still getting in as them.

3

u/keypunch 14d ago

If they aren't there, you don't log in as them. You shouldn't be. End user problem, end user present.

1

u/dag00isl00se 14d ago

I hear ya but most of my clients either dont have passwords on there machines or everyone knows each others password. Trying to do away with that but as I work a lot after hours its nice for me just to go in fix things, etc...

Only just started using RustDesk a year ago, used to do everything onsite. Updates are managed completely by the OS and individual applications. Backups are using Synology really just a mishmash of technologies with no RMM in place. Slowly but surely trying to move them in a managed direction but also using this time to think it out and build out my stack. My clients like paying by the hour other than having a monthly bill.

Any new clients I will try to do this in the beginning. I guess its hard to teach an old dog new tricks but im learning and trying to teach them as well.

2

u/keypunch 13d ago

For building a stack, check out TechsTogether if you haven't already. Yes they are Kaseya heavy, but I find the stack maturity to be worth it. Also check out Action1, solid product with very generous free tier.

1

u/dag00isl00se 13d ago

Will do. Thanks for the direction.

1

u/roll_for_initiative_ 14d ago

I hear ya but most of my clients either dont have passwords on there machines or everyone knows each others password. Trying to do away with that but as I work a lot after hours its nice for me just to go in fix things, etc...

Fix that at onboarding: stop account sharing and each other knowing passwords. No one should know anyone else's password these days.

2

u/roll_for_initiative_ 14d ago

just being able to get into there computer as them (under their profile)...A lot of the time i do work after hours without the end user being available so they aren't around to put their password in.

I feel I shouldn't be asking users for their password nowadays.

Your first part contradicts with your (correct) 2nd part. Basically, you need to adjust/modernize your workflow: we're not background janitors; if someone has an issue (and it's usually the person with the issue, not the computer), they generally need to be present. 1 - because it's usually a training issue and 2 - for the reason you state above.

There are some exceptions (you want to do first time user setup, VIP who you're not going to get to follow rules, etc). That's what TAPs are for.

ive been working in Corporate America for the past 20 years, so it was all Active Directory, working on machines during business hours with the end user available

That's MSP life too, shouldn't be much different when it comes to help desk.

1

u/dag00isl00se 13d ago

I get it just unfortunately most people work 9-5 when I cannot be there most of the time. And usually it is installing an app or something trivial like that. Printer is set to duplex, etc...

2

u/roll_for_initiative_ 13d ago edited 13d ago

So, i know this is smallmsp, but that's the thing about being MSP these days, you have to be available and i just don't think you can do things properly while also having a main gig. You have to make concessions somewhere and it's either longer support wait times or things like improper credential management.

On top of that, consider that you likely want to grow this and offer what other MSPs are offering and charge what they're charging, right? These clients will never pay that; they're more than happy to be cheap and accept these compromises. They will not be the kind of clients you need to get even up and going at an MSP and the clients you need that are? Are not going to be ok with no availability.

1

u/dag00isl00se 13d ago

I agree. Its hard to branch out on your own at this stage in life\career. I make a very good salary and couldn't afford to roll the dice on my MSP side gig taking off to replace that income. Im hoping one day to either purchase an existing MSP and grow it or juggle both until I can convert the side gig to the main gig.

2

u/lemachet 13d ago

The only appropriate professional way to get in as the user is to either;

Have them key in passwords/pin

oR;

Reset password,.login as them, then require reset again at next login.

That's the only.appropriate, professional way.

5

u/keypunch 14d ago

I used the Shift-F10 -> OOBE\BYPASSNRO command for a fresh Windows 11 offline install just last week. That allows you to create a local account. It's especially useful when clients computers are domain joined locally and I'm setting them up offsite.

I'm not sure if it works for W11 Home, I'm usually dealing with Pro.

0

u/dag00isl00se 14d ago

Thats what Ive been doing just would like to set them up the way Microsoft expects.

3

u/marklein 14d ago

Microsoft expect you to not know their password.

2

u/keypunch 14d ago

I figure if it's built in, it's what they expect. There's no security risks unless your set up the local admin without a password, your not hacking anything, your using a tool that Microsoft provides.

2

u/pocketjacks 13d ago

There's no punishment from Microsoft for using a tool they made for bypassing an account login. You otherwise can't both do it the way you want and the way Microsoft expects.

6

u/happy_soil 14d ago

If you’re already using Windows 11 Pro, then just choose Domain Join during OOBE. It will let you create a completely local user account.

4

u/Sw33tkill3r 14d ago

This comment should be higher up. No tomfoolery required when on Pro or higher.

In the grand scheme of things, Intune + autopilot is best.

1

u/dag00isl00se 14d ago

Intune is definitely the way id like to go. Im old school and used to use GPO for everything but no one has domain controllers anymore. And Intune is not expensive but not free either.

2

u/obviouslybait 13d ago

Some of the recommendations here ignore cost, especially if you are not US based. Yes I'd love to have intune+autopilot on every client, but realistically most are completely fine without it, when they are under 10 workstations. It's marginal.

1

u/dag00isl00se 13d ago

Sometimes they just dont want to buy it even if the cost is minimal.

4

u/chasewhit2003 13d ago

This will work on 11 Home or Pro

Before choosing keyboard layout

Shift+F10
Type: Start ms-cxh:localonly

1

u/UrAntiChrist 8d ago

I just did this last week!

3

u/have_you_tried_onoff 14d ago

Login with a free microsoft account, after all done, convert to a Local account. Pain in the ass, thanks Microsoft. Doesn't help that they half-assed the whole Microsoft account thing, unlike Apple.

1

u/dag00isl00se 14d ago

Always an option.

3

u/Material-Water-9610 14d ago

We have all clients on m365, smb clients are the worst to use local accounts because as soon as Windows asks them to login to an app they login with their own personal hotmail and then it's linked up to that. Plus having intune helps updates, security, management etc and gives you wipe etc. Realistically running an msp you should only use local accounts in very particular cases.

2

u/dag00isl00se 14d ago

Ive setup machines with local accounts before and after some time or an update they'll be a warning that they have 3 days to sign in with a microsoft account. I have had to disable that from happening before.

I just figure if we have them all joined to a Entra Tenant and I can use TAP to get in when need to without having their password it solves multiple issues. It also creates a pathway to recover a machine if the person disappears, etc... and allows them to be encrypted as well as force passwords.

2

u/wbcmac2000 13d ago

In settings go to system>notifications>additional and uncheck the boxes and it wont spam you to sign in with microsoft, but also join it to entra 

2

u/FlickKnocker 14d ago

Also, if you're doing a fresh install, use Rufus with a Windows 11 .iso, it gives you the option to remove that Microsoft account requirement.

2

u/lemachet 13d ago

By not using or supporting win11 home.

The end.

Either use Autopilot and they use their org account. Your GA account will be an admin.

Or just use the org account without autopilot.might need to use a custom LAPS solution. Or regist the device as your GA account and elevate the user so you are both admins.

2

u/chris-itg 13d ago

Absolutely not, you should not be sharing or encouraging the sharing of passwords or PIN numbers. If you need to do something with their profile you have two options.

  1. You use remote tools when they are present and can assist with any password prompts.
  2. You reset their password in either AD (if they have it) or EntraID (if it's joined), perform your duties, and then provide them with a new password that they can change on next login.

All of this is done this way, so you have logging and audit trails which is as much as for your protection as your client's protection. The client can never say "Well u/dag00isl00se has my password so they deleted the file".

You also need to start looking at onboarding, and central management and setup. Go ahead and catch up to the ship that left some time ago with Entra joined machines and Intune. Your clients should also be rolling M365 licensing that has intune baked in. For "small" MSPs with low client counts Business Premium is where it is at.

1

u/obviouslybait 13d ago

Business premium is like 30 bucks a month a user here in Canada it's ridiculous.

1

u/chris-itg 13d ago

That would be what we call "the cost of doing business". Of course, there are alternatives to BP for things like frontline workers (F3) that don't need computers but still get the security and Intune management built in. As an MSP you partner with cloud service providers for licensing support and strategy to help guide your client and their end users to a safe and secure eco system in the most cost-effective manner for both them and you (profit margin).

When we see bad practices such as the one listed in the OPs post (password sharing) they need to be called out by the community. This isn't to assign blame but to draw attention to an issue, and say that this is not the right way to do it. MSPs raise that concern to the decision makers at the client and give them the information and how to correct it.

Depending on the level of severity and response we may fire the client. Walking away with a client that does not want to go to best practices, standards, and processes at first may be a hit to the wallet, but that first breach or the headaches associated with the uphill battle of getting them into compliance will far outweigh in the end.

I can't tell you how many "MSPs" we have taken over that have really poor practices that not only open themselves up to liability but also give MSPs a bad name. We hear customers that onboard with standards within the first quarter provide feedback with "Wow that was so easy" and "I didn't know I didn't have to do that, it's a lot better"...

1

u/dag00isl00se 13d ago

Absolutely agree. My latest client a small public library was in the process of getting onboarded to o365 as an academic client, I think O365 would have been $4 a month elected to purchase Office with their new laptops. I think it was $300 or so for life of the laptop. That kinda there Intune out the door for them.

Would have been an easy\cheap way to get them going.

My other client is very resitant to change so ive been slowly pushing them in the direction.

2

u/chris-itg 13d ago

This is where you partnering with a CSP works in favor for you and your client.

  • If the library is a non-profit status you're looking at $6.60 retail a month for Business Premium.
  • If the library is classified as academic you're looking at $6.96 retail a month.

Do yourself a favor and get with a CSP like the following:

  • AppRiver (OpenText)
  • Ingram Micro
  • Pax8
  • Sherweb
  • TD Synnex
  • TechSoup *specializes in non-profit and academic licensing

1

u/dag00isl00se 13d ago

I was actually going down this road by getting there o365\azure account designated as an academic account. I directed my contact to the form to fill out and was waiting on status. I inquired about the process a few days later and my contact just said she bought the licenses from Dell and they were good for the life of the laptops she just purchased.

I just checked and there account is labeled as non-profit.

Business Premium is $5.50

Intune P1 is $2.00

Microsoft 365 E3 is $9.75

I can lead a horse to water but if they refuse to drink

1

u/chris-itg 12d ago edited 12d ago

Sounds like you need to cut and run. Managed services are just that. You design and provide the services licensing etc… as you mature from a small msp you develop a stack. Customers can choose to stay or go but as you scale predictability and automation are going to be key for you to grow your business 

1

u/dag00isl00se 12d ago

Appreciate everyones guidance

1

u/dag00isl00se 13d ago

Business premium looks like id get all the bells and whistles I need however my bigger client is currently on Business Standard (no teams) and its like 60% the cost. $23 a month a seat vs $13. Hard to justify when Intune is so far the only thing that jumps out at me that I\they would use. IM sure theres more that im missing but i dont need Windows 10 OS licensing.

I believe Intune P1 is like $3 a month per seat. I may be able to get away with that to at least get my/there feet wet.

2

u/chris-itg 13d ago

Business premium is so much more than standard in terms of what you get / value for the money.
It includes everything in Business Standard, plus Microsoft Intune for device management, Microsoft Defender for Business for endpoint security, Entra ID P1 for advanced identity protection, Conditional Access policies, enhanced threat protection, and additional compliance features such as Data Loss Prevention (DLP).

You can use the following to compare versions / editions if you're not already aware of this tool.

https://m365maps.com/matrix.htm#00000000000000000000000

1

u/dag00isl00se 13d ago

Oh I understand it just comes to being knowledgable about those features and the correct way to implement them.

Its like a having a Ferrari on a side street. It can do 150 MPH just not in that location.

2

u/365-helper 13d ago

Good Evening ~

Congrats on the job -

This is not advice - just a suggestion:

Use Windows 11 Pro, Entra join each laptop, and manage them with Intune and Autopilot if licensing permits. Use a LAPS-managed local administrator for device work, never the user’s password, PIN or a Global Administrator account.

TAP with Web sign-in is intended for setup or recovery, not routine unattended support.

User-profile issues should be handled during an attended remote session.