Sécurité risks in using ‘no @thankyou.com’ to bypass Microsoft compte login during Windows 11 installeration

One du recommended methods for bypassing Microsoft compte login during the Windows 11 OOBE is to attempt to log in using a locked compte (no @thankyou.com being the most commonly recommended compte to use). This causes an erreur sur le server side that would ensuite allow Windows to be installé using a local compte.

Though il y a other methods to bypass the login, such as the OOBE\BYPASSNRO method, some may prefer or require to use the ‘locked compte’ method over others due to simplicity, time constraints or otherwise wishing to keep an active connection during setup (eg. for preliminary mises à jour). Using a random gibberish domain as opposed to a known, registered domain reportedly fails occasionally to trigger the server-side erreur allowing a local compte to be used. Je suis déjà aware duse alternative methods, so Je sun’est pas asking for them to be explained ici.

In various discussions on this general topic, there ont été sécurité concerns raised about attempting to use a locked compte tied vers le owner of a domain such as ‘thankyou.com’ (which in this case happens to be Citibank).

As suggested in a comment in this question, could the domain owner be granted privileges remotely over an OS installé this way? Is there some facility dans le backend of Microsoft’s servers that would allow for an attack vector like this?

J’ai done this many times using the following method.

It has a fonctionné every time for me.

Je ne peux pas see a reason using the method you describe so if il y a indeed a reason, veuillez enlighten me. I certainly ne know tout.

Désactiver internet requirements

On the “Sign in” page, use these steps:

Use the “Shift + F10” clavier raccourci to open Invite de commandes.

Tapez the following command to release the current réseau configuration and appuyez sur Enter:
oobe\bypassnro

Quick note: The command is a single phrase sans spaces.

Ordinateur will boot automatiquement, and vous pouvez need to start the out-of-box experience again.

Cliquez sur le “Je n’ai pas internet” option.

@VolodymyrKotylo has informed me that an addition step is required although J’ai not seen it myself.

“One more step is needed après redémarrer: “ipconfig /release” sur le sign
in écran. And après that appuyez sur “go back” and vous allez see the username
input écran”

Source (even though I déjà knew comment do this, the person I scraped this text from deserves credit)