Windows 10: Windows hello for business implementation

Discus and support Windows hello for business implementation in Windows 10 Software and Apps to solve the problem; Hello looking for idea here for whfb.Have a hybrid join environment. Looking to move to passwordless authentication and need to prevent users from... Discussion in 'Windows 10 Software and Apps' started by labadmin1, May 23, 2025 at 10:17 AM.

  1. labadmin1 Win User

    Windows hello for business implementation


    Hello looking for idea here for whfb.Have a hybrid join environment. Looking to move to passwordless authentication and need to prevent users from being able to login using password. Need to keep availabilty for admin account login and also not break apps that still use password to authenticate like company portal. Thanks for any help

    :)
     
  2. Junaid_A Win User

    Windows 10 Hello for Business with Physical Smartcard and roaming uses across shared PC's

    Hi Rosenbrier,



    Thank you for writing to Microsoft Community Forums.



    With the recent ratification of security keys by FIDO, Windows Hello allows security authentication for shared devices that allows full roaming experience. For more information, I would suggest you to refer to the article
    Windows Hello and FIDO2 Security Keys enable secure and easy authentication for shared
    devices
    and see if it helps.



    If you have any further query regarding the same, I would suggest you to post your query in the
    IT Pro TechNet Forums, where we have support professionals well equipped with the
    knowledge on Windows Hello for Business.



    Additional Info:



    Regards,
     
  3. Determine why Windows Hello is unavailable on a Surface Book

    Microsoft changed how Windows Hello worked on Domain-joined computers with build 1607, the "Anniversary Update".

    Previously, Windows Hello on a business computer worked pretty much the same as it did on a home computer. It was more or less a stored password that was "triggered" by the chosen acceptable authentication methods.

    Now it is based on certificates and other things that are generally much more secure.

    If no changes are made in Group Policy on the Domain, a computer had an earlier build (such as 1511) of Windows 10 and a user had configured Windows Hello, and then the computer was updated to build 1607, that same user would still be able to use the same Windows Hello authentication methods. Any users trying to set up Windows Hello for the first time post-upgrade or just on build 1607 would not be able to.

    The domain administrators must configure the new Group Policies controlling Windows Hello for Business before any of the authentication methods will work on computers running Windows 10 build 1607.

    For more information and for the specific settings that must be set, please read the following official documents from Microsoft:

     
  4. Windows hello for business implementation

    Can't enable Windows Hello - Some settings are managed by your organization

    I found the solution. The reason is that Windows Hello is managed differently on domain joined computers, starting with the anniversary update.
    To get it to work you have to follow these steps:

    1) Setup a Group Policy Central Store (you should already have that)

    2) Get Windows 10 Anniversary Update Group Policy Templates. You can do so by copying your files from PolicyDefinitions (in windir on a Win10 Anniversary Update machine) into the PolicyDefinitions of the central store. You might copy those files first to a file share, because of permissions your regular user should not have on the central store.

    3) Setup a new GPO or add to an existing the following settings to enable Windows Hello:

    • Computer Configuration/Policies/Administrative Templates

    .../Windows Components/Windows Hello For Business/ Use biometrics => Enabled

    .../Windows Components/Windows Hello for Business/ Use a hardware security device => Enabled (if you want to use TPM instead of key or certificate based activation for Windows Hello). Note that in general all business computers should have TPM

    .../System/Logon/ Turn on convenience PIN sign-in => Enabled (This is the key. This enables PIN sign-in which in turn will enable Hello, together with the other settings.)

    .../Windows Components/Biometrics/ Allow domain users to log on using biometrics => Enabled (I think this is enabled by default, but being explicit makes GP management a lot easier.)

    You will find more optional configuration possibilities in System/Logon and Windows Components/Biometrics and Windows Components/Windows Hello for Business.

    You will find more background here:
    Changes to Convenience PIN / Windows Hello Behavior in Windows 10 Version 1607

    and here

    https://technet.microsoft.com/en-us...ement-microsoft-passport-in-your-organization

    Most important excerpt:

    If you want to use key or certificate based Windows Hello you can follow the guides in the links. Don't get confused though. You can still use regular TPM for normal Windows Hello.
     
Thema:

Windows hello for business implementation

Loading...
  1. Windows hello for business implementation - Similar Threads - hello business implementation

  2. Windows hello for business implementation

    in Windows 10 Gaming
    Windows hello for business implementation: Hello looking for idea here for whfb.Have a hybrid join environment. Looking to move to passwordless authentication and need to prevent users from being able to login using password. Need to keep availabilty for admin account login and also not break apps that still use...
  3. Windows Hello for Business Implementation Issues

    in Windows 10 Gaming
    Windows Hello for Business Implementation Issues: Hello,We are currently experiencing issues with the implementation of Windows Hello for Business in our organization. Our devices are hybrid-joined and updated to the latest 23H2 build, we activated the GPO mentioned in Microsoft's documentation here: Windows Hello for...
  4. Windows Hello for Business Implementation Issues

    in Windows 10 Software and Apps
    Windows Hello for Business Implementation Issues: Hello,We are currently experiencing issues with the implementation of Windows Hello for Business in our organization. Our devices are hybrid-joined and updated to the latest 23H2 build, we activated the GPO mentioned in Microsoft's documentation here: Windows Hello for...
  5. Windows Hello for Business

    in Windows 10 Gaming
    Windows Hello for Business: We are piloting Windows Hello for Business on laptops running Windows 10 21H2. Hello is configured to used Cloud Hybrid Trust recommended and for the majority of the 70 users trialling all is good. What is now hard to ignore is 2 users have randomly hit an intermittent issue...
  6. Windows Hello for Business

    in Windows Hello & Lockscreen
    Windows Hello for Business: We are piloting Windows Hello for Business on laptops running Windows 10 21H2. Hello is configured to used Cloud Hybrid Trust recommended and for the majority of the 70 users trialling all is good. What is now hard to ignore is 2 users have randomly hit an intermittent issue...
  7. Windows Hello for Business

    in Windows 10 Software and Apps
    Windows Hello for Business: Even with Windows Hello enforced via policy in Microsoft Intune, users can still sign in via single authentication using their password. I am currently testing if Windows Hello for Business is a viable MFA or Passwordless solution. Is there a way to make users use their...
  8. Windows hello for business

    in Windows 10 Gaming
    Windows hello for business: where do I find the newest documentation on hello for business? https://answers.microsoft.com/en-us/windows/forum/all/windows-hello-for-business/65cbde06-638c-4cfc-aa81-d05e1484921b
  9. Windows hello for business

    in Windows 10 Software and Apps
    Windows hello for business: where do I find the newest documentation on hello for business? https://answers.microsoft.com/en-us/windows/forum/all/windows-hello-for-business/65cbde06-638c-4cfc-aa81-d05e1484921b
  10. Windows hello for business

    in AntiVirus, Firewalls and System Security
    Windows hello for business: where do I find the newest documentation on hello for business? https://answers.microsoft.com/en-us/windows/forum/all/windows-hello-for-business/65cbde06-638c-4cfc-aa81-d05e1484921b