Intune Let's keep your account secure

Anthony Hill 6 Reputation points
2026-09-01T00:31:36.46+00:00

Hi,

Background, we are a college who are using MFA for staff using MS Authenticator and Temporary Access Pass codes.

Currently have activated Authentication methods (in Migration Complete mode) - Policies and using Microsoft Authenticator and Temporary Access Pass for staff but nothing setup for students.

When a student goes to use the Work or School method to connect their device to the college network after assigning the device they are presented with "Let's keep your account secure" and after "next" they are prompted with a "Contact your admin" (you are required to register an authentication method to continue but none have been enabled for this account. Contact your admin for help. > OK".

I do not want students to enrol or use MFA at all.
Can this be done, and why are students getting a prompt for this, even though they are not required/wanted to use MFA?

By default in Conditional Access there is a rule for staff for MFA and none for students.

Thanks.

:)

Microsoft Security | Intune | Enrollment
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-01T00:31:52.1666667+00:00

    Yes. Students can be kept off MFA, but the current sign-in flow is still asking them to register an authentication method because no authentication method is enabled for those student accounts while the sign-in/enrollment experience is invoking authentication method registration.

    For an education tenant, the documented approach is:

    1. In Authentication Methods, target Phone, SMS, and Microsoft Authenticator to staff and exclude students.
    2. If using passwordless onboarding for students, target Temporary Access Pass to students.
    3. For Windows student devices, it is typical to disable Windows Hello for Business tenant-wide so students are not asked to set up multifactor authentication during sign-in.

    Why the prompt appears:

    • Windows Hello for Business is enabled by default on Windows devices.
    • Setting it up requires users to perform multifactor authentication.
    • In student scenarios where MFA is not enabled for students, this can result in the “Let’s keep your account secure” flow and then “Contact your admin” because no allowed authentication method is available for that account.

    What to change:

    1. In the Microsoft Intune admin center, go to Devices > By platform > Windows > Device onboarding > Enrollment.
    2. Select Windows Hello for Business.
    3. Set Configure Windows Hello for Business to Disabled.
    4. Save the change.

    Also verify enrollment settings:

    1. In Microsoft Intune admin center, go to Devices > Enroll devices > Automatic Enrollment.
    2. Confirm MDM user scope is set appropriately for the users enrolling devices. If provisioning packages are used, it must be All.
    3. Set MAM user scope to None.

    If the goal is no MFA for students at all, keep student accounts excluded from Microsoft Authenticator/phone/SMS methods and disable Windows Hello for Business for the student enrollment path. If passwordless sign-in for students is needed later, the documented option is to issue Temporary Access Pass to students instead.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.