Single Sign-On fails on Windows 10 Fall Creators Update for users in a Workgroup
Last Modified: 2024-01-06 09:19:43 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Single Sign-On fails on Windows 10 Fall Creators Update for users in a Workgroup
Technical Articles ID:
KB89857
Last Modified: 2024-01-06 09:19:43 Etc/GMT Environment
Drive Encryption (DE) 7.2.2 and later Problem
For users in a Workgroup, Single Sign-on fails on the Windows 10 Fall Creators Update. This issue applies only to a Windows Workgroup. Enterprise customers whose systems are in a Windows domain aren't affected. Cause
With the Settings, Accounts, Sign-in options, Privacy, Use my sign-in info to automatically finish setting up my device after an update or restart. This feature is an advanced Windows Update feature. It uses sign-in information to automatically finish setting up a device after an update. With the Windows 10 Fall Creators Update, it has been extended to regular reboots and shutdowns. Microsoft's aim is to get the last user on the computer back to a locked state, rather than a signed-out state, after a user-initiated power cycle. This design, together with the automatic restoration, aims at a continuation of user experience across the power cycle. It's similar to locking or putting the device to sleep. This feature change causes the DE credential provider to fail to understand if the current user logging into Windows is having their first attempt at the Windows logon screen. DE needs to determine whether to capture the credentials to be replayed for Single Sign-on (SSO) later. NOTES:
Solution
Customers who use DE in a Workgroup environment need to disable the policy option under Windows Settings before they enable the DE Password Sync and SSO policy options:
Affected ProductsLanguages:This article is available in the following languages: |
|