Windows 10: None of Hello Windows will work across a domain

Discus and support None of Hello Windows will work across a domain in Windows Hello & Lockscreen to solve the problem; I've a simple setup with one server running Win 2016 Essential as a domain with a number of Dell XPS laptops. All are on the latest updates but I've... Discussion in 'Windows Hello & Lockscreen' started by Cayman Blue, Dec 8, 2020.

  1. None of Hello Windows will work across a domain


    I've a simple setup with one server running Win 2016 Essential as a domain with a number of Dell XPS laptops. All are on the latest updates but I've never been able to get any of the Hello Windows functionality to work once the laptop is connected to the domain.


    Instead I get a notice that suggests I've blocked the functionality via Group Policies...


    None of Hello Windows will work across a domain 5efc43ba-84a9-4123-8f15-04be71c60a75?upload=true.png


    I don't seem to be the only person with this issue and I've tried various group policy settings suggested across the MS forums and other help sites but nothing works.


    This should not be so difficult according to all the MS instructions, it should work out of the box given I have compatible hardware and using vanilla functionality across both server and client devices.


    Any suggestions gratefully received.

    :)
     
    Cayman Blue, Dec 8, 2020
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Dec 8, 2020
    #2
  3. Windows 'domain'?

    Hello,

    Thank you for sharing your concern in the Microsoft Community. Follow these steps to find the domain name:

    • Press the Windows key + R then choose System.
    • The name of your computer will be listed as the Full computer name.
    • The domain your computer belongs to will be listed as the Domain. If, instead of Domain, you see Workgroup, your computer
      is not a member of any domain.

    If you have any questions or things you'd like to clarify, feel free to ask.
     
    Marvin Barc, Dec 8, 2020
    #3
  4. None of Hello Windows will work across a domain

    Windows Hello With Domain Account

    Hello,

    I would like to sign into my PC with Windows Hello using my laptop's fingerprint sensor. However, I sign into Windows using a domain account, not a local or Microsoft account. Apparently, Windows Hello is not enabled by default for domain accounts. I am
    curious as to how I can enable it. Should I check the Group Policy on my Domain Controller? If so, where would I find it in Group Policy? I have already tried enabling "Enable PIN sign-on" in Group Policy, but that did not work. My laptop is running Windows
    10 1909 and my DC is running Windows Server 2012 R2.

    Any suggestions would be appreciated.
     
    Jonathan Heitz, Dec 8, 2020
    #4
Thema:

None of Hello Windows will work across a domain

Loading...
  1. None of Hello Windows will work across a domain - Similar Threads - None Hello across

  2. Windows hello for domain users

    in Windows 10 Gaming
    Windows hello for domain users: setting up Windows Hello seems to work perfectly. After a while minutes, hours, but not days the Windows Hello forgets their face and PIN, forcing them to log back in with a password. Once in their profile, all the settings for the facial recognition and PIN are missing....
  3. Windows Hello Pin not working after domain change

    in Windows Hello & Lockscreen
    Windows Hello Pin not working after domain change: E-mail domain has been changed and after that i am unable to login using Windows hello Pin https://answers.microsoft.com/en-us/windows/forum/all/windows-hello-pin-not-working-after-domain-change/a91cb446-322d-4e82-b95c-61de8cc2576f
  4. Windows Hello Pin not working after domain change

    in Windows 10 Gaming
    Windows Hello Pin not working after domain change: E-mail domain has been changed and after that i am unable to login using Windows hello Pin https://answers.microsoft.com/en-us/windows/forum/all/windows-hello-pin-not-working-after-domain-change/a91cb446-322d-4e82-b95c-61de8cc2576f
  5. Windows Hello Pin not working after domain change

    in Windows 10 Software and Apps
    Windows Hello Pin not working after domain change: E-mail domain has been changed and after that i am unable to login using Windows hello Pin https://answers.microsoft.com/en-us/windows/forum/all/windows-hello-pin-not-working-after-domain-change/a91cb446-322d-4e82-b95c-61de8cc2576f
  6. Domain Trust across enterprise

    in Windows 10 Gaming
    Domain Trust across enterprise: I Have a requirement to establish trust between two Domains part of different network. Domain A users to be authenticated in Domain B systems using their computer resources. Only a group of people in domain A needs authentication. One way Trust only. Both Domain A and Domain...
  7. Domain Trust across enterprise

    in Windows 10 Software and Apps
    Domain Trust across enterprise: I Have a requirement to establish trust between two Domains part of different network. Domain A users to be authenticated in Domain B systems using their computer resources. Only a group of people in domain A needs authentication. One way Trust only. Both Domain A and Domain...
  8. Windows Hello on my domain not working anymore

    in Windows Hello & Lockscreen
    Windows Hello on my domain not working anymore: Hello,I'm facing an issue with sign-in options in my Windows 10 devices on my domain. I've made changes in my Group Policy Management to comply with some parameters to enable Windows Hello. I can't create an alternative sign-in mode such as PIN or fingerprint to login into...
  9. Windows Hello on my domain not working anymore

    in Windows 10 Gaming
    Windows Hello on my domain not working anymore: Hello,I'm facing an issue with sign-in options in my Windows 10 devices on my domain. I've made changes in my Group Policy Management to comply with some parameters to enable Windows Hello. I can't create an alternative sign-in mode such as PIN or fingerprint to login into...
  10. Windows Hello on my domain not working anymore

    in Windows 10 Software and Apps
    Windows Hello on my domain not working anymore: Hello,I'm facing an issue with sign-in options in my Windows 10 devices on my domain. I've made changes in my Group Policy Management to comply with some parameters to enable Windows Hello. I can't create an alternative sign-in mode such as PIN or fingerprint to login into...