Allow password logon

This section describes how to set whether or not to allow Windows local accounts without authenticators to log on with only a password when “Limit sign-in options” is enabled.

Operation Procedure

Select Authentication Service > Group Policy from the menu.

  1. Click the policy you want to configure from the group policy list.
    Group policy
  2. Click the setting icon for “Allow password logon” in the Logon item of the Two-Factor Authentication Settings to change the setting.
    Group policy
  3. Click the “Update” button.
  4. Click “OK” on the confirmation message.

Set value

  • Disabled
    If “Limit sign-in options” is enabled, not all accounts on the PC can log on with only a password.

    e.g.)

    Account Status of authenticator settings How to logon
    User1 Registered as a certified device Logon with FIDO Logon
    User2 Certified device not registered logon disabled

  • Enabled
    Even if “Limited sign-in options” is enabled, accounts that are not registered with an authenticator on the PC will be able to log on using only a password.

    e.g.)

    Account Status of authenticator settings How to logon
    User1 Registered as a certified device Logon with FIDO Logon
    User2 Certified device not registered Logon with a password