Windows 10: Windows Hello for Business and Kerberos Trust

Discus and support Windows Hello for Business and Kerberos Trust in Windows 10 Gaming to solve the problem; We're having an issue with setting up WHfB in our hybrid environment. DC is server 2016 and devices are Entra Hybrid Joined, although I've tested with... Discussion in 'Windows 10 Gaming' started by IndependentCarry4093, Jan 21, 2025.

  1. Windows Hello for Business and Kerberos Trust


    We're having an issue with setting up WHfB in our hybrid environment. DC is server 2016 and devices are Entra Hybrid Joined, although I've tested with an Entra joined only laptop and it's the same. The Kerberos Trust Server has been successfully set up on the DC the only one in the estate. The relevant WHfB settings have been applied to a test user group. The user can successfully set up WHfB on their device and cached tickets can be seen when running klist. The cached tickets are removed when the user locks the device or signs out, as expected, however they are never generated again after

    :)
     
    IndependentCarry4093, Jan 21, 2025
    #1

  2. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what about the decommissioning of the AD FS?

    Hello,

    Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.

    We have understood that during the migration from the on-premise deployment to the hybrid deployment, we have to force users to re-enroll them with Windows Hello for Business. Please correct me if I am wrong.

    Now we are wondering, what would be the impact if we decommission the AD FS before having redeployed all our users to the hybrid scenario "Cloud Kerberos Trust"?

    • For users not migration to the hybrid deployment, will WHFB still work without AD FS?
    • What will happen if the certificate delivered by the internal certificate authority get expired? Will the certificate still be renewed by the PKI, without going through the AD FS? Or will the user get stuck, with a none working PIN?

    Thanks.
     
    BUSSIERE Florian, Jan 21, 2025
    #2
  3. BUSSIERE Florian, Jan 21, 2025
    #3
  4. Windows Hello for Business and Kerberos Trust

    What are the requirements to use Windows Hello for Business with Azure Files?

    Hello everyone,

    We want to move all our data and infrastructure from on-prem to Azure Files, but I need to make sure that Windows Hello for Business works flawlessly with Azure Files. I can't find ressources about the integration between these two technologies and the requirements.

    So, here are my questions:

    If I use AADDS (Azure Active Directory Domain Services) with Azure Files, will it work automatically with WHFB?

    If not, then what are the requirements? It looks like I still need ADDS (Active Directory Domain Services) and could use "Cloud Trust" or AAD Kerberos. AAD Kerberos seems to be very promising but one of the requirements is Windows 11 "Enterprise". So, my other question is: Does AAD Kerberos works with Windows 11 Business?

    Thank you very much for the help!
     
    Frédéric Grondin, Jan 21, 2025
    #4
Thema:

Windows Hello for Business and Kerberos Trust

Loading...
  1. Windows Hello for Business and Kerberos Trust - Similar Threads - Hello Business Kerberos

  2. Windows Hello for Business and Kerberos Trust

    in Windows 10 Software and Apps
    Windows Hello for Business and Kerberos Trust: We're having an issue with setting up WHfB in our hybrid environment. DC is server 2016 and devices are Entra Hybrid Joined, although I've tested with an Entra joined only laptop and it's the same. The Kerberos Trust Server has been successfully set up on the DC the only one...
  3. W10 What do I do to get rid of warmomg Windows Hello for Business cloud Kerberos trust

    in Windows 10 Software and Apps
    W10 What do I do to get rid of warmomg Windows Hello for Business cloud Kerberos trust: Event view show these message Event Viewer started in 2022.I am a Home user. No business. Only user on the system.There is not gpedit.msc on a W10 home system.Warning shows User Device Registration Event ID 360Windows Hello for Business provisioning will not be launched....
  4. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows 10 Gaming
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  5. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows 10 Software and Apps
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  6. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows Hello & Lockscreen
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  7. Windows Hello For Business Cloud Trust

    in Windows Hello & Lockscreen
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  8. Windows Hello For Business Cloud Trust

    in Windows 10 Gaming
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  9. Windows Hello For Business Cloud Trust

    in Windows 10 Software and Apps
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  10. Windows hello for business on premise certification trust

    in Windows Hello & Lockscreen
    Windows hello for business on premise certification trust: Hello, i have tried to follow guide from microsoft https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-cert-trust-adfs and upon "Configure the Registration Authority" step, i encounter error [ATTACH] This is my system...