ENO is a Windows feature that lets you use your phone to sign into your computer

ENO stands for "Extensible Network Object" and is a Windows authentication method that uses your phone as a second factor when you sign in. Instead of typing a password, you can approve a sign-in request on your phone, or use your phone's biometric (fingerprint or face recognition) to confirm it's really you. Windows then grants access to your computer.

ENO works with Windows 10 and Windows 11 on computers connected to a Microsoft Entra ID account — the account system used by organizations, schools, and some personal Microsoft accounts. Your phone must have the Microsoft Authenticator app installed and set up beforehand. When you try to sign in to your computer, a notification appears on your phone asking you to approve or deny the request.

The main reason organizations use ENO is security. A password alone can be stolen or guessed. A phone approval adds a second check that only you can perform, because only you have your phone. This makes it much harder for someone else to access your account, even if they know your password.

Key Takeaways

  • ENO uses your phone to confirm your identity when signing into Windows, replacing or supplementing a typed password.
  • You need the Microsoft Authenticator app on your phone and a Microsoft Entra ID account on your computer to use ENO.
  • When you sign in, a notification appears on your phone asking you to approve the request before Windows grants access.
  • ENO is most common in workplace and school environments where security requirements are stricter than personal use.

How ENO sign-in works step by step

When you sit down at your Windows computer and ENO is enabled, the sign-in screen looks different from a normal password screen. Instead of a password field, you see a message telling you to check your phone. At the same time, a notification arrives on your phone through the Microsoft Authenticator app.

The notification shows your computer's name and asks you to approve or deny the sign-in. You tap "Approve" on your phone — or if your phone has biometric security set up, you may need to use your fingerprint or face to confirm the approval. Once you approve, Windows unlocks and you can use your computer normally. If you tap "Deny," the sign-in fails and you stay on the lock screen.

The whole process usually takes 10 to 30 seconds. If you don't respond within a few minutes, the request times out and you can try again. Some organizations also let you fall back to a password if your phone is unavailable, though this depends on how your IT department configured ENO.

Where ENO is used and who sets it up

ENO is most common in workplaces and schools that use Microsoft Entra ID (formerly called Azure Active Directory). Your IT department or system administrator decides whether to turn on ENO for your account. You cannot turn it on yourself — it must be enabled on the organization's side first.

Personal Microsoft accounts can use ENO in some cases, but it is less common. If you use a personal account and want to check whether ENO is available, you can look in your Microsoft account security settings, though most personal users rely on passwords or Windows Hello (which uses your computer's camera or fingerprint reader instead of your phone).

Once your organization enables ENO, you need to set up the Microsoft Authenticator app on your phone and link it to your account. Your IT department usually provides instructions for this setup. After that, ENO works automatically the next time you sign in to a computer where it is enabled.

ENO compared to other Windows sign-in methods

Windows offers several ways to sign in, and they work differently. A password is something you type and remember. Windows Hello uses your computer's built-in camera or fingerprint reader to recognize your face or fingerprint — no phone needed. ENO uses your phone to approve the sign-in remotely.

ENO is stronger than a password alone because it requires both something you know (your password, if you set one) and something you have (your phone). Windows Hello is convenient because you do not need to carry anything extra, but it only works on that specific computer. ENO works across multiple computers as long as they are all set up for it and connected to your organization's network.

Some organizations use ENO and Windows Hello together. You might use Windows Hello to unlock your computer quickly during the day, but if you sign out and sign back in, ENO kicks in as an extra security layer. The exact setup depends on your organization's policies.

What to do if ENO is not working

If you see the ENO sign-in screen but your phone does not receive a notification, first check that the Microsoft Authenticator app is installed and you are signed into it with the correct account. Make sure your phone has an internet connection — ENO requires a data or Wi-Fi connection to send and receive notifications.

If your phone is offline or the app is not working, most organizations allow you to use an alternative sign-in method. This might be a password, a PIN, or a security key. Your IT department can tell you what options are available. If you have lost your phone or cannot access it, contact your IT support team — they can temporarily disable ENO on your account so you can sign in another way while you sort out your phone situation.

If ENO keeps failing even when your phone is online and the app is working, restart both your phone and your computer. If the problem continues, your organization's IT support can check whether ENO is properly configured on your account and whether there are any network issues blocking the connection.

Security considerations with ENO

ENO is more secure than a password alone because someone would need both your account password and physical access to your phone to sign in. However, it is not perfect. If someone steals your phone and knows your password, they could potentially approve a sign-in request before you notice the phone is gone.

To reduce this risk, keep your phone locked with a PIN or biometric security. This way, even if someone has your phone, they cannot approve ENO requests without unlocking it first. Also, review your Microsoft Authenticator app settings regularly to make sure only your devices are registered to your account.

If you suspect your phone has been compromised or stolen, contact your IT department immediately. They can remove your phone from your account and prevent any further sign-in attempts using that device. This is faster and more secure than waiting to see if someone tries to use it.

Frequently Asked Questions

Can I use ENO if I do not have a smartphone?

No, ENO requires a smartphone with the Microsoft Authenticator app. If you do not have a smartphone, your organization should provide an alternative sign-in method, such as a password, PIN, or hardware security key. Contact your IT department to find out what options are available to you.

What happens if I get a new phone?

You need to set up the Microsoft Authenticator app on your new phone and link it to your account. Your IT department can guide you through this process. Until you complete the setup, you will not be able to use ENO on your new phone, so have a backup sign-in method ready.

Does ENO work if my phone is in airplane mode?

No, ENO requires an internet connection to send and receive notifications. If your phone is in airplane mode or has no data or Wi-Fi connection, you will not receive the sign-in notification. Turn off airplane mode or connect to the internet before trying to sign in.

Can someone else approve an ENO sign-in request on my phone?

If your phone is unlocked, yes — anyone holding your phone could tap "Approve" on an ENO notification. This is why it is important to keep your phone locked with a PIN or biometric security. If your phone requires a fingerprint or face scan to unlock, an attacker cannot approve requests without your biometric data.

Is ENO the same as two-factor authentication?

ENO is a form of two-factor authentication, but not all two-factor authentication uses ENO. Two-factor authentication means using two different methods to prove your identity. ENO uses your phone as the second factor. Other methods include text message codes, security keys, or authenticator apps that generate time-based codes.