Windows 10: Unable to use Windows Hello on Domain account

Discus and support Unable to use Windows Hello on Domain account in Windows Hello & Lockscreen to solve the problem; Windows Hello not working under domain account. I have tried the guide below but no luck. Kindly share if any solution available for this issue.... Discussion in 'Windows Hello & Lockscreen' started by RL_2019, Jul 3, 2019.

  1. RL_2019 Win User

    Unable to use Windows Hello on Domain account


    Windows Hello not working under domain account. I have tried the guide below but no luck. Kindly share if any solution available for this issue.

    https://www.surfacetablethelp.com/2018/04/cannot-enable-windows-hello-on-domain-joined-pc-with-windows-10-1709.html


    OS: Windows 10 Pro

    Version: 1803

    OS Build: 17134.858


    ***Original title: Surface Pro 4 - Windows Hello not working for Domain Account***

    :)
     
    RL_2019, Jul 3, 2019
    #1
  2. changari Win User

    Raising the windows domain and forest issues?


    hi,

    I run a domain that was all 2003 r2 servers. I recently upgraded all my domain controllers to windows 2012 r2.
    That went off without any problems.. Our trust relationships had no issues also.

    My first step was to raise the Domain and Forest levels past 2003 to 2008. This went off without a hitch.
    These are the features for raising the levels to 2008:

    • Features and benefits include all default Active Directory features, all features from the Windows Server 2003 domain functional level, plus:
    • Read-Only Domain Controllers – Allows implementation of domain controllers that only host read-only copy of NTDS database.
    • Advanced Encryption Services – (AES 128 and 256) support for the Kerberos protocol.
    • Distributed File System Replication (DFSR) – Allows SYSVOL to replicate using DFSR instead of older File Replication Service (FRS). It provides more robust and detailed replication of SYSVOL contents.

    Forest Level Windows Server 2008

    • Features and benefits include all of the features that are available at the Windows Server 2003 forest functional level, but no additional features. All domains that are subsequently added to the forest will operate at the Windows Server 2008 domain functional level by default.


    My next step is to raise the domain and forest to 2008 r2, then 2012, and finally 2012 r2. I have been trying to find out exactly what I could expect from raising the Domain and Forest for each step.

    The step involving 2008 r2 seems relatively a non issue. But getting the couple of new features seem very nice

    Domain Level Windows Server 2008 R2

    • All default Active Directory features, all features from the Windows Server 2008 domain functional level, plus 2 new features

    Forest Level Windows Server 2008 R2

    • All of the features that are available at the Windows Server 2003 forest functional level, plus the following features:


    • Active Directory Recycle Bin, which provides the ability to restore deleted objects in their entirety while AD DS is running. <== New Feature very cool
    • All domains subsequently added to the forest will operate at the Windows Server 2008 R2 domain functional level by default.

    Here is my big concerns for the next raising of domain and forest to 2012.

    Forest Level Windows Server 2012:

    • All of the features that are available at the Windows Server 2008 R2 forest functional level, but no additional features.
    • All domains subsequently added to the forest will operate at the Windows Server 2012 domain functional level by default.

    Domain Level Windows Server 2012 R2: <=====
    Need to investigate more and why this post

    • DC-side protections for Protected Users. Protected Users authenticating to a Windows Server 2012 R2 domain can no longer:


    • Authenticate with NTLM authentication <==============(what issues may arise)
    • Use DES or RC4 cipher suites in Kerberos pre-authentication
    • Be delegated with unconstrained or constrained delegation
    • Renew user tickets (TGTs) beyond the initial 4-hour lifetime


    Will this affect my exchange anywhere users with remote access authenticating either clear of NTLM???
    and what would/may not to work properly day 1 when I raise the domain and forest to 2012. I cant really find anyone that can answer a straight question.

    Has anyone gone through this? what problems did you have, if any , if a lot???

    Any thoughts and suggestions will be much appreciated??

    thanks


    - - - Updated - - -

    One more point... I am not sure if I posted this to the correct forum.. So if I was wrong and it should be in a different one..
    PLEASE LET ME KNOW
     
    changari, Jul 3, 2019
    #2
  3. Windows 'domain'?

    Hello,

    Thank you for sharing your concern in the Microsoft Community. Follow these steps to find the domain name:

    • Press the Windows key + R then choose System.
    • The name of your computer will be listed as the Full computer name.
    • The domain your computer belongs to will be listed as the Domain. If, instead of Domain, you see Workgroup, your computer
      is not a member of any domain.

    If you have any questions or things you'd like to clarify, feel free to ask.
     
    Marvin Barc, Jul 3, 2019
    #3
  4. Unable to use Windows Hello on Domain account

    Question for some1 with windows domain knowledge

    I know there isnt a whole lot of server admins here, but I thought I would ask.

    At my work we had our office domain server go down due to windows corruption. Since they have still been able to login to their accounts using the server that went down. So they picked the ADMIN domain in the their drop down list.

    Now that i'm rebuilding the ADMIN server I want to make sure they can use the same accounts and still have all of their my documents data and such. I want to know where is their ADMIN user data and authentication being kept. Would it be the other domain on the network? or on their local machines?

    Note* there is no trust setup from what i can tell between the two servers. And their accounts dont exist in active directory on the other server.

    Any help is appreciated
     
    Hybrid_theory, Jul 3, 2019
    #4
Thema:

Unable to use Windows Hello on Domain account

Loading...
  1. Unable to use Windows Hello on Domain account - Similar Threads - Unable Hello Domain

  2. Windows Hello Unavailable for Domain Managed Account but working for local account

    in Windows 10 Software and Apps
    Windows Hello Unavailable for Domain Managed Account but working for local account: My new company-owned laptop does not have the option to sign in using Windows Hello -- Fingerprint, Pin and Facial Recognition are all unavailable. Error Messages say: "This option is currently unavailable" "Something went wrong. Try again later". Note: I don't want/need...
  3. Windows Hello Unavailable for Domain Managed Account but working for local account

    in Windows 10 Gaming
    Windows Hello Unavailable for Domain Managed Account but working for local account: My new company-owned laptop does not have the option to sign in using Windows Hello -- Fingerprint, Pin and Facial Recognition are all unavailable. Error Messages say: "This option is currently unavailable" "Something went wrong. Try again later". Note: I don't want/need...
  4. Unable to use Windows Hello Fingerprint

    in Windows Hello & Lockscreen
    Unable to use Windows Hello Fingerprint: Hi, I use Windows Hello Fingerprint to log into my laptop. Recently, whenever I put my finger on the scanner, it would say "Your PIN is required to sign in." I did some digging on the internet, and one source said that I should set Credential Manager vaultsvc to automatic....
  5. Windows Hello when logging into domain account

    in Windows Hello & Lockscreen
    Windows Hello when logging into domain account: I have the option to use Windows Hello for facial rec or fingerprint on a local pc account but I don't have the option to use it on a domain account. I get the message that the option is unavailable. I have already run the gpedit settings and regedit to enable...
  6. Unable to use Microsoft Store on Domain machine - stuck in Windows Hello Registration Loop

    in Windows Hello & Lockscreen
    Unable to use Microsoft Store on Domain machine - stuck in Windows Hello Registration Loop: Hello Everyone, A few weeks ago, as I logged on I was asked to setup Windows Hello on my machine. It's a Surface Pro and domain joined. It didn't work, but it let me log in and get on with my work, so forgot about it. At the same time the YourPhone app stopped working...
  7. Unable to login using Windows Hello!

    in Windows Hello & Lockscreen
    Unable to login using Windows Hello!: Hi, When I purchased my HP Z Book Studio G5, I was able to login using either my fingerprint or my face. But after sometime, I think after some Windows update both features stopped working soWindows Hello Face or Windows Hello Fingerprint does not show up anymore during...
  8. Windows Hello With Domain Account

    in Windows Hello & Lockscreen
    Windows Hello With Domain Account: Hello, I would like to sign into my PC with Windows Hello using my laptop's fingerprint sensor. However, I sign into Windows using a domain account, not a local or Microsoft account. Apparently, Windows Hello is not enabled by default for domain accounts. I am curious as to...
  9. Unable to use Windows Hello Fingerprint

    in AntiVirus, Firewalls and System Security
    Unable to use Windows Hello Fingerprint: I am unable to use windows hello fingerprint after installing my new windows 10. I have checked every options and contacted to Microsoft support as well. It was working fine for couple of days after installing the Windows 10. See below for error code. [ATTACH]...
  10. Surface Pro 4 - Windows Hello not working for Domain Account

    in Windows 10 Software and Apps
    Surface Pro 4 - Windows Hello not working for Domain Account: Windows Hello not working under domain account. I have tried the guide below but no luck. Kindly share if any solution available for this issue. https://www.surfacetablethelp.com/2018/04/cannot-enable-windows-hello-on-domain-joined-pc-with-windows-10-1709.html OS: Windows...

Users found this page by searching for:

  1. windows hello unable to locate domain controller