Hi,
The reason we need SDL is to allow a new device to on-board using Windows AutoPilot.
We're using AP in Hybrid mode so it needs visibility of a domain controller to be able to authenticate the user. As its a new machine there are no locally stored profiles to use cached creds.
I wondered if a machine cert would do the trick. Once signed in the user could use 365 authentication which works fine post login.
I'll look into the machine cert. Do you think it would work for what we're looking to do?
Thanks