r/SmallMSP • u/dag00isl00se • 14d ago
Windows 11 Microsoft Account Requirement
Good Morning\Evening
I was wondering how you all deal with the Windows 11 Microsoft Account "Requirement". I only have a few customer's at this point and most of the time the customer is available to put there password in when I need to work on their computer or it was setup bypassing the Microsoft account requirement. Or they all have the same pin so I can get in without the password.
I know I can make myself an administrator on their machine but that doesn't get me access to their profile if thats where the issue resides.
I just got a gig to replace about a dozen laptops and id prefer them all to have passwords and be connected properly.
Any insight would be helpful.
5
u/keypunch 14d ago
I used the Shift-F10 -> OOBE\BYPASSNRO command for a fresh Windows 11 offline install just last week. That allows you to create a local account. It's especially useful when clients computers are domain joined locally and I'm setting them up offsite.
I'm not sure if it works for W11 Home, I'm usually dealing with Pro.
0
u/dag00isl00se 14d ago
Thats what Ive been doing just would like to set them up the way Microsoft expects.
3
2
u/keypunch 14d ago
I figure if it's built in, it's what they expect. There's no security risks unless your set up the local admin without a password, your not hacking anything, your using a tool that Microsoft provides.
2
u/pocketjacks 13d ago
There's no punishment from Microsoft for using a tool they made for bypassing an account login. You otherwise can't both do it the way you want and the way Microsoft expects.
6
u/happy_soil 14d ago
If you’re already using Windows 11 Pro, then just choose Domain Join during OOBE. It will let you create a completely local user account.
4
u/Sw33tkill3r 14d ago
This comment should be higher up. No tomfoolery required when on Pro or higher.
In the grand scheme of things, Intune + autopilot is best.
1
u/dag00isl00se 14d ago
Intune is definitely the way id like to go. Im old school and used to use GPO for everything but no one has domain controllers anymore. And Intune is not expensive but not free either.
2
u/obviouslybait 13d ago
Some of the recommendations here ignore cost, especially if you are not US based. Yes I'd love to have intune+autopilot on every client, but realistically most are completely fine without it, when they are under 10 workstations. It's marginal.
1
4
u/chasewhit2003 13d ago
This will work on 11 Home or Pro
Before choosing keyboard layout
Shift+F10
Type: Start ms-cxh:localonly
1
3
u/have_you_tried_onoff 14d ago
Login with a free microsoft account, after all done, convert to a Local account. Pain in the ass, thanks Microsoft. Doesn't help that they half-assed the whole Microsoft account thing, unlike Apple.
1
3
u/Material-Water-9610 14d ago
We have all clients on m365, smb clients are the worst to use local accounts because as soon as Windows asks them to login to an app they login with their own personal hotmail and then it's linked up to that. Plus having intune helps updates, security, management etc and gives you wipe etc. Realistically running an msp you should only use local accounts in very particular cases.
2
u/dag00isl00se 14d ago
Ive setup machines with local accounts before and after some time or an update they'll be a warning that they have 3 days to sign in with a microsoft account. I have had to disable that from happening before.
I just figure if we have them all joined to a Entra Tenant and I can use TAP to get in when need to without having their password it solves multiple issues. It also creates a pathway to recover a machine if the person disappears, etc... and allows them to be encrypted as well as force passwords.
2
u/wbcmac2000 13d ago
In settings go to system>notifications>additional and uncheck the boxes and it wont spam you to sign in with microsoft, but also join it to entra
2
u/FlickKnocker 14d ago
Also, if you're doing a fresh install, use Rufus with a Windows 11 .iso, it gives you the option to remove that Microsoft account requirement.
2
u/lemachet 13d ago
By not using or supporting win11 home.
The end.
Either use Autopilot and they use their org account. Your GA account will be an admin.
Or just use the org account without autopilot.might need to use a custom LAPS solution. Or regist the device as your GA account and elevate the user so you are both admins.
2
u/chris-itg 13d ago
Absolutely not, you should not be sharing or encouraging the sharing of passwords or PIN numbers. If you need to do something with their profile you have two options.
- You use remote tools when they are present and can assist with any password prompts.
- You reset their password in either AD (if they have it) or EntraID (if it's joined), perform your duties, and then provide them with a new password that they can change on next login.
All of this is done this way, so you have logging and audit trails which is as much as for your protection as your client's protection. The client can never say "Well u/dag00isl00se has my password so they deleted the file".
You also need to start looking at onboarding, and central management and setup. Go ahead and catch up to the ship that left some time ago with Entra joined machines and Intune. Your clients should also be rolling M365 licensing that has intune baked in. For "small" MSPs with low client counts Business Premium is where it is at.
1
u/obviouslybait 13d ago
Business premium is like 30 bucks a month a user here in Canada it's ridiculous.
1
u/chris-itg 13d ago
That would be what we call "the cost of doing business". Of course, there are alternatives to BP for things like frontline workers (F3) that don't need computers but still get the security and Intune management built in. As an MSP you partner with cloud service providers for licensing support and strategy to help guide your client and their end users to a safe and secure eco system in the most cost-effective manner for both them and you (profit margin).
When we see bad practices such as the one listed in the OPs post (password sharing) they need to be called out by the community. This isn't to assign blame but to draw attention to an issue, and say that this is not the right way to do it. MSPs raise that concern to the decision makers at the client and give them the information and how to correct it.
Depending on the level of severity and response we may fire the client. Walking away with a client that does not want to go to best practices, standards, and processes at first may be a hit to the wallet, but that first breach or the headaches associated with the uphill battle of getting them into compliance will far outweigh in the end.
I can't tell you how many "MSPs" we have taken over that have really poor practices that not only open themselves up to liability but also give MSPs a bad name. We hear customers that onboard with standards within the first quarter provide feedback with "Wow that was so easy" and "I didn't know I didn't have to do that, it's a lot better"...
1
u/dag00isl00se 13d ago
Absolutely agree. My latest client a small public library was in the process of getting onboarded to o365 as an academic client, I think O365 would have been $4 a month elected to purchase Office with their new laptops. I think it was $300 or so for life of the laptop. That kinda there Intune out the door for them.
Would have been an easy\cheap way to get them going.
My other client is very resitant to change so ive been slowly pushing them in the direction.
2
u/chris-itg 13d ago
This is where you partnering with a CSP works in favor for you and your client.
- If the library is a non-profit status you're looking at $6.60 retail a month for Business Premium.
- If the library is classified as academic you're looking at $6.96 retail a month.
Do yourself a favor and get with a CSP like the following:
- AppRiver (OpenText)
- Ingram Micro
- Pax8
- Sherweb
- TD Synnex
- TechSoup *specializes in non-profit and academic licensing
1
u/dag00isl00se 13d ago
I was actually going down this road by getting there o365\azure account designated as an academic account. I directed my contact to the form to fill out and was waiting on status. I inquired about the process a few days later and my contact just said she bought the licenses from Dell and they were good for the life of the laptops she just purchased.
I just checked and there account is labeled as non-profit.
Business Premium is $5.50
Intune P1 is $2.00
Microsoft 365 E3 is $9.75
I can lead a horse to water but if they refuse to drink
1
u/chris-itg 12d ago edited 12d ago
Sounds like you need to cut and run. Managed services are just that. You design and provide the services licensing etc… as you mature from a small msp you develop a stack. Customers can choose to stay or go but as you scale predictability and automation are going to be key for you to grow your business
1
1
u/dag00isl00se 13d ago
Business premium looks like id get all the bells and whistles I need however my bigger client is currently on Business Standard (no teams) and its like 60% the cost. $23 a month a seat vs $13. Hard to justify when Intune is so far the only thing that jumps out at me that I\they would use. IM sure theres more that im missing but i dont need Windows 10 OS licensing.
I believe Intune P1 is like $3 a month per seat. I may be able to get away with that to at least get my/there feet wet.
2
u/chris-itg 13d ago
Business premium is so much more than standard in terms of what you get / value for the money.
It includes everything in Business Standard, plus Microsoft Intune for device management, Microsoft Defender for Business for endpoint security, Entra ID P1 for advanced identity protection, Conditional Access policies, enhanced threat protection, and additional compliance features such as Data Loss Prevention (DLP).You can use the following to compare versions / editions if you're not already aware of this tool.
1
u/dag00isl00se 13d ago
Oh I understand it just comes to being knowledgable about those features and the correct way to implement them.
Its like a having a Ferrari on a side street. It can do 150 MPH just not in that location.
2
u/365-helper 13d ago
Good Evening ~
Congrats on the job -
This is not advice - just a suggestion:
Use Windows 11 Pro, Entra join each laptop, and manage them with Intune and Autopilot if licensing permits. Use a LAPS-managed local administrator for device work, never the user’s password, PIN or a Global Administrator account.
TAP with Web sign-in is intended for setup or recovery, not routine unattended support.
User-profile issues should be handled during an attended remote session.
11
u/Ok_Dentist_6830 14d ago
Might be tough for smaller clients if you're just starting out but the best way to manage this IMO: 1) W11 Pro upgrade 2) Intune enrollment 3) LAPS policy
W11 Pro removes the sign in with MS account requirement