After the Computer Logon Client policy has been created or updated, users must first sign in to their computers using their domain accounts (so that the newly created or updated policy can be downloaded to the computers).

Thereafter, the MFA is enabled & enforced on local accounts

Sign in with a local account, e.g. "2FA Local"

You'll be prompted to verify using the credentials of the mapped domain account, e.g. "la\2fa"



  • No labels