<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=23&amp;t=2678" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-07-23T00:09:39+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=23&amp;t=2678</id>
<entry>
<author><name><![CDATA[thefunk]]></name></author>
<updated>2017-07-23T00:09:39+01:00</updated>
<published>2017-07-23T00:09:39+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2678&amp;p=9676#p9676</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2678&amp;p=9676#p9676"/>
<title type="html"><![CDATA[[Question]Yubi + Domain Account + Windows Hello For Business]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2678&amp;p=9676#p9676"><![CDATA[
I have a Windows 10 Pro virtual desktop that is connected to a local Active Directory Domain.<br /><br />I'd like to sign in to my domain account on said machine, remotely by plugging in the Yubikey to my thin client. Through USB over IP, I can make my remote machine see my Yubikey when it is plugged into the thin client. I have verified that this functionality is working.<br /><br />Here's the difficult part. I'll be connecting to my machine remotely using an obscure protocol, and I'll have no way of entering a password or a pin when connecting. <br /><br />In short, I need the domain sign in to be handled entirely by the Yubikey. I read up on PIV a little, and that looks useful, but you still need a pin for sign-ins.<br /><br />So my question is, can you sign in to a domain account without a pin or passphrase or other second authentication factor? If so, is Windows Hello For Business what I'm looking for? Are there other solutions I should be looking into? Ideally I'd like to do this without buying anything Azure, as I'm a broke college student, but if I have to buy an Azure AD instance to get this functionality, I'm sure I could work something out.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4857">thefunk</a> — Sun Jul 23, 2017 12:09 am</p><hr />
]]></content>
</entry>
</feed>