Remove Biometrics and Pin, and Disable Password Login options
On Azure AD–joined Windows 10/11 devices, users can sign in offline using the Primary Refresh Token (PRT) that’s cached locally. If you’ve already revoked their PRT from the cloud, they may still be able to unlock the device with a cached password—or, if they use Windows Hello for Business (WHfB), with a PIN or biometric. … [Read more…]