Currently:
If a user is offline, and if he has lost/broken one authenticator (if 2FA deployed with 'something you know' + 'something you have'), he can't login to his laptop (as 'Emergency Password' doesn't work offline).

Alternative:
Creating a fail open mode:
• If user is online, only 2FA methods are displayed
• But if users is offline, the AD password only method is also displayed (so user can connect with only one method (something you know): his AD password).

Comments