First Access
When a resource is added and no people are linked yet, nobody can pass MFA on it — including the founder. This is intentional: access is explicit, never assumed. The panel calls this state First Access and guides you through it.
Connecting yourself
Section titled “Connecting yourself”On the resource page, the First Access callout offers Connect myself:
- Pick the Windows account you sign in with on that machine (e.g.
Administrator). - If you haven’t enrolled an authenticator yet, scan the QR shown right there.
- Verify with a code — done. You are now linked, and once MFA is enforced you can sign in with your own factor.
The panel shows a clear badge on resources still waiting for their first person, so an accidentally enforced-but-empty machine can’t hide.
Domain controllers
Section titled “Domain controllers”On a domain controller, Connect myself is intentionally unavailable. Add the Windows account manually and send yourself (or the responsible admin) a normal invitation instead.
Why this design
Section titled “Why this design”Deriving access from existing Windows usernames would silently grant people you never chose. First Access keeps the rule consistent: a machine has zero relationships until someone explicitly creates them — safe for you on day one, and safe at fleet scale.