Today, this method of protection in terms of 2FA is not quite relevant, there are more and more methods of hacking using social engineering. Therefore, a reasonable solution in this case is to secure your system from the inside at the windows login stage of the user. Generating one-time passwords using various security tokens contributes to a guaranteed level of protection for winlogon directly. And if the system is protected from the inside, when the password of the system user has guaranteed protection by the method of windows two factor authentication it is safe to say that this method is more rational to use.