Windows 10: Windows Hello for Business key trust configuration with ADFS

Discus and support Windows Hello for Business key trust configuration with ADFS in Windows Hello & Lockscreen to solve the problem; I'm looking to implement windows hello for business key trust modern managed topology with an ADFS server so mitigate the AAD connect sync back to on... Discussion in 'Windows Hello & Lockscreen' started by TheRusseller_064, May 25, 2021.

  1. Windows Hello for Business key trust configuration with ADFS


    I'm looking to implement windows hello for business key trust modern managed topology with an ADFS server so mitigate the AAD connect sync back to on premise to map the public key to the AD user attribute.Do you know what configurations in ADFS are required for this configuration?

    :)
     
    TheRusseller_064, May 25, 2021
    #1

  2. ADFS SAML setup

    Hello,

    I have questions regarding ADFS SAML configuration.

    I have been charged with setting up ADFS SAML and connecting our system with clarity safetyzone.

    I am using Using windows serv 2019 platform for the servers. I have created a test environment that has a domain controller, server with ADCS, and another server with ADFS. I have a certificate created within the ADCS server and I installed ADFS on the
    respective server. I verified after installation of the role and configuring an adfs administrator that the adfs administrator can sign into the https://sts.contoso.com/adfs/ls/idpinitiatedsignon.aspx, I created a windows test account and logged into the
    adfs server for testing purposes and when navigating to the https://sts.contoso.com/adfs/ls/ and attempting to sign in with that user, I get an error:

    An error occurred
    An error occurred. Contact your administrator for more information.
    Error details
    Activity ID: f68cc99a-b6e5-40dc-1a00-0080000000e5Error details: MSIS7065: There are no registered protocol handlers on path /adfs/ls/ to process the incoming request.Node name: 85253664-435b-4d04-8775-d4b96854cb12Error time: Mon, 02 Nov 2020 20:11:16 GMTCookie:
    enabledUser agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36

    I have everyone permitted for intranet access in the Access Control Policies.
    Am i missing something? Once i can verify that a standard user can login, then i can move on to the step of setting up the appropriate claims/trusts.

    Does anyone have experience with this and maybe even experience with the Clarity Safety Zone platform?
     
    JosephStefanelli, May 25, 2021
    #2
  3. adfs 4.0

    Thanks Skypper for the reply Windows Hello for Business key trust configuration with ADFS :)

    Basically i am not updating TLS, i support adfs which is configured with 2016 server and we have a sso(relying party trust) created with one of the vendor.

    I received a e-mail stating they are plannning to update the TLS 1.1 to 1.2, all i want to know is will it impact active SSO configuration.

    And also on a note my adfs configured with third party SSL certificate.

    Thanks in advanceWindows Hello for Business key trust configuration with ADFS :)
     
    RakeshShetty1, May 25, 2021
    #3
  4. Windows Hello for Business key trust configuration with ADFS

    ADFS Integration

    Hi,

    Actually we are developing an Enterprise SaaS Application (Mobile Application which calls a web API) hosted on Azure App service , and we need to build our application to integrate with customers through ADFS. That allows customer's employees to use the
    on-premises active directory identity to access our services seamlessly.

    We are totally aware of the ADFS different protocols/relaying party trust configuration/tokens/Claims but still we have a question

    Q: Should we as a service provider (Resource Owner) build an ADFS farm ( as per Reference : Federate with a customer's AD FS - Azure Architecture Center )
    OR just develop our application to redirect the request to the customer's ADFS (Account owner) and validate tokens of the customer....... (as per Reference : https://docs.microsoft.com/en-us/wi...ad-fs/overview/ad-fs-scenarios-for-developers)
    ?

    Thanks,

    Omnia
     
    omniayehia, May 25, 2021
    #4
Thema:

Windows Hello for Business key trust configuration with ADFS

Loading...
  1. Windows Hello for Business key trust configuration with ADFS - Similar Threads - Hello Business key

  2. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows 10 Gaming
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  3. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows 10 Software and Apps
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  4. Windows Hello For Business Cloud Trust

    in Windows Hello & Lockscreen
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  5. Windows Hello For Business Cloud Trust

    in Windows 10 Gaming
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  6. Windows Hello For Business Cloud Trust

    in Windows 10 Software and Apps
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  7. Deploy Windows Hello for Business Cloud Trust using Intune

    in Windows Hello & Lockscreen
    Deploy Windows Hello for Business Cloud Trust using Intune: Hi,I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trustFirst I tried using GPO and it works well. I can see the event 358...
  8. Deploy Windows Hello for Business Cloud Trust using Intune

    in Windows 10 Gaming
    Deploy Windows Hello for Business Cloud Trust using Intune: Hi,I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trustFirst I tried using GPO and it works well. I can see the event 358...
  9. Deploy Windows Hello for Business Cloud Trust using Intune

    in Windows 10 Software and Apps
    Deploy Windows Hello for Business Cloud Trust using Intune: Hi,I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trustFirst I tried using GPO and it works well. I can see the event 358...
  10. Windows hello for business on premise certification trust

    in Windows Hello & Lockscreen
    Windows hello for business on premise certification trust: Hello, i have tried to follow guide from microsoft https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-cert-trust-adfs and upon "Configure the Registration Authority" step, i encounter error [ATTACH] This is my system...