maciejrebisz.com

IT

Microsoft Intune – Passport for Work – Mobile-First Cloud-First

maximios February 2, 2023

This is a new feature that will be released in the next service update of Microsoft Intune in January 2016.

I have been playing around with this feature for a couple of months in my test tenant and at a customer in Denmark.

The reason for I’m so excited for this feature, is that we had 300 new Windows 10 devices that would be Azure AD joined. The users was from the age of 6 – 10 years old, and when the devices was AzureAD joined as part of the OOBE, the Windows 10 Device will automatic enable PIN login instead of password login. That is a cool feature – but when PIN login is enabled AzureAD requires a phone number from the user to be able reset the PIN at another point.

This feature is called Two-step validation – and is not the same as Multi Factor validation in AzureAD premium. See White Paper by Microsoft Azure-AD-Windows-10-better-together

The Azure Authenticator allows you to secure your account with two-step verification. With two-step verification, you sign in using something you know (your password) and something you have (your mobile device).

Passport for Work Settings

“Passport for Work” can be found in the Microsoft Intune console http://manage.microsoft.com

Under Administration -> Mobile Device Management -> Windows -> Passport for Work

When my “Passport for Work” was enabled none was selected and I was not able to AzureAd join a Windows 10 device. I was fixed by “Disable Passport for Work on enrolled devices”

This setting is tenant wide – and in my tenant cannot be enabled or disable by user/device groups.

Passport  for Work “Enable Passport for Work on enrolled devices”

Now you can make the settings as it fits your organization needs.

Use a Trusted Platform Module (TPM)

Can be preferred or required

Has to be a minimum PIN of 4 characters.

Has a maximum PIN length of 127 characters.

This blogpost will be updated when this feature goes GA.

Related Posts

IT /

Intune – Windows device enrollment restrictions – Cloud First

IT /

How to add “hidden” Windows UWP to Windows Store for Business – Cloud First

IT /

Office 2016 Active Directory-Based activation – Cloud First

‹ How to install CU1 on SCCM R2 SP1 – Mobile-First Cloud-First › Changes to “group-based licensing” in Azure AD are coming soon – Mobile-First Cloud-First

Recent Posts

  • Intune – Windows device enrollment restrictions – Cloud First
  • How to add “hidden” Windows UWP to Windows Store for Business – Cloud First
  • Office 2016 Active Directory-Based activation – Cloud First
  • How to deploy Windows Local Experience Packs with Intune – Cloud First
  • Conditional Access for Outlook Web Access (OWA) – Cloud First

Recent Comments

No comments to show.

Archives

  • November 2025
  • October 2025
  • August 2025
  • July 2025
  • June 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • September 2024
  • July 2024
  • June 2024
  • March 2024
  • December 2023
  • August 2023
  • June 2023
  • March 2023
  • February 2023
  • December 2022
  • September 2022
  • August 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • January 2022
  • December 2021
  • October 2021
  • September 2021
  • August 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • February 2020
  • January 2020
  • December 2019
  • October 2019
  • September 2019
  • June 2019
  • April 2019
  • March 2019
  • February 2019
  • March 2018
  • February 2018
  • December 2017
  • October 2017
  • August 2017

Categories

  • IT

Back to Top

© maciejrebisz.com 2026
Powered by WordPress • Themify WordPress Themes