Defender Desktop Login is not enumerating the user's Active Directory groups correctly.
说明
When using Desktop Login, it is behaving as if it cannot reach Active Directory; for example defaulting to 'Windows Authentication' unexpectedly if the option "Require Specified Users to Log On using Defender"
原因
If the AD user does not have the permission "SELF | Read" then this may occur.
解决办法
Ensure that the permission "SELF | Read" is enabled.
其他信息
If "SELF | Read" is not sufficient, also test "Authenticated Users | Read"