How to disable forced password login when Windows login agent is installed
Objective
When the Windows login agent is installed, it enforces password-based login as the default authentication method on the Windows login screen. As a result, other authentication methods such as Windows Hello (Face, PIN) or Smart Card login become optional and are not presented as primary login methods. This article explains how to disable the forced password login behavior.
Prerequisites
- Administrative privileges on the target machine
- Administrator access to the Group Policy Management Console (GPMC)
Steps to follow
Manual method : Update settings on a single machine
Press Windows + R to open the Run dialog box.
Type regedit and press Enter.
If prompted by User Account Control, click Yes to allow the Registry Editor to make changes.
Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\ZOHO CORP\ADSelfService Plus Client Software.
Locate the key named ShowSelectedTile.
- Modify the value of ShowSelectedTile to FALSE.
Click OK.
Using a GPO: Update settings on multiple machines
Step 1: Create a new GPO
- Log in to the domain controller with administrative credentials.
Press Windows + R to open the Run dialog box.
Type gpmc.msc and press Enter to open the GPMC.
On the left pane, navigate to Group Policy Objects.
Right-click Group Policy Objects and select New.
In the New GPO dialog box, enter a name for the GPO (e.g., ADSSP_LoginAgent_Tile_Disable).
Click OK.
Step 2: Edit the newly created GPO
- Right-click the GPO you just created.
Select Edit. This will open the Group Policy Management Editor.
In the Group Policy Management Editor, navigate to Computer Configuration > Preferences > Windows Settings > Registry.
Step 3: Add the registry entry to enable the login bypass
Right-click Registry on the left pane.
Navigate to New > Registry Item.
In the New Registry Properties window, configure the following:
- Action: Update
Hive: HKEY_LOCAL_MACHINE
- Key Path: SOFTWARE\WOW6432Node\ZOHO Corp\ADSelfService Plus Client Software
- Value name: ShowSelectedTile
- Value type: REG_SZ
- Value data: false
- Base: String (default option)
Click Apply, then OK.
Step 4: Link the GPO
- Close the editor.
- Link the GPO to the relevant OU or domain.
- Apply the GPO to the target machines by running the following:
gpupdate /force Validation and confirmation
How to reach support
If the issue persists, contact our support team here.
New to ADSelfService Plus?