Windows 10: Do I need Azure premium for cloud hybrid trust / key hybrid trust or not?

Discus and support Do I need Azure premium for cloud hybrid trust / key hybrid trust or not? in Windows 10 Gaming to solve the problem; Hello, we'd like to setup Windows Hello for Business to get MFA for Windows logon. We have fully on premise environment and tight budget - can't afford... Discussion in 'Windows 10 Gaming' started by mik256, Apr 13, 2023.

  1. mik256 Win User

    Do I need Azure premium for cloud hybrid trust / key hybrid trust or not?


    Hello, we'd like to setup Windows Hello for Business to get MFA for Windows logon. We have fully on premise environment and tight budget - can't afford Azure Premium subsriptions for our users. My question is: on MS sites, it is said you need Azure Premium for certificate trust. What about kerberos cloud hybrid trust and key hybrid trust. Can we go without subscriptions? I have already tried to set it up, successfully setup pin, but constantly getting errors when try to login with the pin:- 0xc000005e PIN code is not available and this function is not supported in your organization - this opti

    :)
     
    mik256, Apr 13, 2023
    #1
  2. Antuanfff Win User

    Deploy Windows Hello for Business Cloud Trust using Intune

    Hi,

    I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: Windows Hello for Business cloud Kerberos trust deployment

    First I tried using GPO and it works well. I can see the event 358 saying WHfB cloud trust is enabled and the computer got the TGT ticket. Everything works fine.

    But then I removed the GPO and tried using Intune. The users are prompted to create the PIN and they are able to log in but it fails randomly. I checked the event viewer and now in the event 358 it says that Cloud Trust is not enabled and the TGT ticket is "not tested"

    Both the configuration profiles in Intune (enablement with OMA uri and PIN Reqs) are applied, the state is "Succeded" for the computers. Why is Cloud Trust not enabled? I guess everything is ok in AD and the computer as when I enable the GPO it works fine and I can see how the secret is stored and read in Azure AD. Thanks

    Regards.
     
    Antuanfff, Apr 13, 2023
    #2
  3. Jan_EW Win User
    Cloud Trust with Azure ADJoinedDevices

    Hello

    I'm trying to setup cloud trust for WHFB. The login with face or finger works fine, the only thing not working is the authentication to on prem-resources.

    When i login with Whfb and try to start an application really any (Exporer, Browser, Windows Settings) following Pop-Up appears.


    Do I need Azure premium for cloud hybrid trust / key hybrid trust or not? 6be4180f-6320-495c-acfa-3ae9c747bfb4?upload=true.png


    When using Username and password I'm able to view the resources, fingerprint and face are not accepted.

    When trying to view or get my krbgt ticket I get following error:


    Do I need Azure premium for cloud hybrid trust / key hybrid trust or not? 56645ac7-18e7-4c98-8e1d-a02ec5be51d2?upload=true.png


    So from my understanding cloud trust doesn't send the credentials to verify to on prem AD am i correct?

    Here is some Additional Info that might help:


    Do I need Azure premium for cloud hybrid trust / key hybrid trust or not? b58dec41-046c-47f4-a530-fc12199c2619?upload=true.png



    Do I need Azure premium for cloud hybrid trust / key hybrid trust or not? 0c5b0853-b65c-4c15-91f2-d209e9ca3cbb?upload=true.png


    I Cant find any useful articles, so I'm hoping to get some help here.



    I followed MS instruction from here: Windows Hello for Business cloud Kerberos trust deployment

    Server and Clients fulfill the Requirements

    Oma-Uri is correct

    Thanks in Advance

    Regards

    Jan
     
    Jan_EW, Apr 13, 2023
    #3
  4. Do I need Azure premium for cloud hybrid trust / key hybrid trust or not?

    Azure and on-prem (hybrid) and NTP best practices

    Hello all

    For those of you in an Azure hybrid environment (i.e. on-prem and Azure with DCs in each) did you make any changes to NTP on Azure machines or are you using the out of box configuration when using NTP? I assume people are leaving the default for all machines in Azure and following best practices for on-prem and pointing to the PDC? Can you please advise? What is best practice?
     
    matrixmaestro, Apr 13, 2023
    #4
Thema:

Do I need Azure premium for cloud hybrid trust / key hybrid trust or not?

Loading...
  1. Do I need Azure premium for cloud hybrid trust / key hybrid trust or not? - Similar Threads - need Azure premium

  2. Cloud Kerberos trust for hybrid domain join machines &WHFB

    in Windows 10 Gaming
    Cloud Kerberos trust for hybrid domain join machines &WHFB: Hi All,I want to deploy Windows hello for business for Hybrid domain joined devices with cloud Kerberos trust. Most of the articles and online videos are discussing WHFB is for AAD joined devices not for Hybrid join devices.Is there any guide to implement Cloud Kerberos trust...
  3. Cloud Kerberos trust for hybrid domain join machines &WHFB

    in Windows 10 Software and Apps
    Cloud Kerberos trust for hybrid domain join machines &WHFB: Hi All,I want to deploy Windows hello for business for Hybrid domain joined devices with cloud Kerberos trust. Most of the articles and online videos are discussing WHFB is for AAD joined devices not for Hybrid join devices.Is there any guide to implement Cloud Kerberos trust...
  4. Do I need Azure premium for cloud hybrid trust / key hybrid trust or not?

    in Windows 10 Software and Apps
    Do I need Azure premium for cloud hybrid trust / key hybrid trust or not?: Hello, we'd like to setup Windows Hello for Business to get MFA for Windows logon. We have fully on premise environment and tight budget - can't afford Azure Premium subsriptions for our users. My question is: on MS sites, it is said you need Azure Premium for certificate...
  5. Cloud Trust with Azure ADJoinedDevices

    in Windows Hello & Lockscreen
    Cloud Trust with Azure ADJoinedDevices: Hello I'm trying to setup cloud trust for WHFB. The login with face or finger works fine, the only thing not working is the authentication to on prem-resources.When i login with Whfb and try to start an application really any Exporer, Browser, Windows Settings following...
  6. Cloud Trust with Azure ADJoinedDevices

    in Windows 10 Gaming
    Cloud Trust with Azure ADJoinedDevices: Hello I'm trying to setup cloud trust for WHFB. The login with face or finger works fine, the only thing not working is the authentication to on prem-resources.When i login with Whfb and try to start an application really any Exporer, Browser, Windows Settings following...
  7. Cloud Trust with Azure ADJoinedDevices

    in Windows 10 Software and Apps
    Cloud Trust with Azure ADJoinedDevices: Hello I'm trying to setup cloud trust for WHFB. The login with face or finger works fine, the only thing not working is the authentication to on prem-resources.When i login with Whfb and try to start an application really any Exporer, Browser, Windows Settings following...
  8. Azure AD Hybrid environment with on prem

    in Windows 10 Gaming
    Azure AD Hybrid environment with on prem: I have an existing domain in PA but I want to avoid purchasing a lot of equipment to start a domain in MIA. If I were to choose Azure AD instead on purchasing an On-prem and a server license; purchase all the equipment needs for a on-prem setup isn't neccessary, I can create...
  9. Azure AD Hybrid environment with on prem

    in Windows 10 Software and Apps
    Azure AD Hybrid environment with on prem: I have an existing domain in PA but I want to avoid purchasing a lot of equipment to start a domain in MIA. If I were to choose Azure AD instead on purchasing an On-prem and a server license; purchase all the equipment needs for a on-prem setup isn't neccessary, I can create...
  10. Hybrid

    in Windows 10 Software and Apps
    Hybrid: I got Windows 11 today and for some reason it's a weird hybrid of 10 and 11, it has the Windows 11 taskbar, start menu, search, icons and widgets, it even says its Windows 11 in WinVer. But settings, file explorer, notifications, calander are still the Windows 10 design....