Customize Windows Login Screen with Hyprlink for self service

fadyaz
fadyaz used Ask the Experts™
on
Hello,

I have  Web Applications for reset passwords and unlock accounts ( self service). i need to integerate this solution with the users login screen inside the organizations.

by letting the users press on Forgot Password or Self Service link under the login screen then it will open web browser with predefined page for our solution.

is this doable or no ? we have WIndows 10 & Windows 8.1 Machines in the channel.

Regards,
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Distinguished Expert 2018

Commented:
I don't think it's doable for the following reason:
The logon screen is shown without anyone being logged on. Any application that you try to integrate into that screen will be launched without authentication, so it will run with system permissions (highest local permissions) which is a potential security risk.

It would be better to  setup something like an assigned access user that may only start a browser. Are you familiar with assigned access? That would be suitable and that could be deployed.

Author

Commented:
Thanks for your reply McKnife. can you please explain more about the assigned access and suggested steps ?
Distinguished Expert 2018
Commented:
For a test: create a weak local user account "testuser".
As Administrative user, open an elevated powershell and launch
Set-AssignedAccess -UserName testuser -AUMID Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge

Open in new window

Now logon as testuser and see if edge starts and if you can reach your self service page.

(tested here on win10 v1709)
Acronis in Gartner 2019 MQ for datacenter backup

It is an honor to be featured in Gartner 2019 Magic Quadrant for Datacenter Backup and Recovery Solutions. Gartner’s MQ sets a high standard and earning a place on their grid is a great affirmation that Acronis is delivering on our mission to protect all data, apps, and systems.

Author

Commented:
Amazing idea but does it work with windows 8.1 ?
Distinguished Expert 2018

Commented:
I don't know, I tested only with 10. Assigned access had bugs on previous versions of win10 - no idea whether it is fixed on 8.1. But assigned access did already exist on 8.1 - try it out.
Ajay ChananaMCSE-2003/08|RHCSA| VCP5/6 |vExpert2018
Distinguished Expert 2017

Commented:
thought the above cannot customised , windows has already given you provision to create password recovery disk/usb

for the self service portal user can access that from any other system or login to local user guest account and can access it.

above are workaround I hope that helps

Author

Commented:
McKnife thanks alot it is worked for me fine but is there a way to run it with out the web bar and for it to open a specific web page ??

or found a way to run internet explorer in kiosk mode but can i force intenet explorer to run  instead of Edge ?
Distinguished Expert 2018

Commented:
The idea was: don't open a security hole just for a password reset. So I voted for assigned access which, as far as I know and heard, is flawless when it comes to security. If you wanted to use internet explorer, you cannot use assigned access, since IE is not a modern app and ass. access is limited to modern apps. So please decide what is more important, security or comfort.

I have no idea how to set a start page on edge inside of assigned access, but let me try. Hang on.
Distinguished Expert 2018

Commented:
Ok, tested.
You can set a start page as you always would: using GPOs for edge. Make a user GPO apply to that reset user (testuser) that sets it. Works.
Distinguished Expert 2018

Commented:
You should also disable that reset user when other accounts are logged on so that it cannot be used for anything but assigned access.
That can be achieved by deploying a scheduled task that disables the account whenever someone logs on.

Author

Commented:
Apperciate your help on this .
Distinguished Expert 2018

Commented:
Welcome.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial