Windows 10: Windows hello for business on premise certification trust

Discus and support Windows hello for business on premise certification trust in Windows Hello & Lockscreen to solve the problem; Hello, i have tried to follow guide from microsoft... Discussion in 'Windows Hello & Lockscreen' started by Garyyyyyyyyyyy, Mar 24, 2021.

  1. Windows hello for business on premise certification trust


    Hello,


    i have tried to follow guide from microsoft https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-cert-trust-adfs and upon "Configure the Registration Authority" step, i encounter error


    Windows hello for business on premise certification trust f7219b6b-83f3-4162-ad66-2d83b399b3c7?upload=true.png



    This is my system information

    Windows hello for business on premise certification trust 47b1fa21-1f87-4397-921a-55f09b07b76c?upload=true.png

    :)
     
    Garyyyyyyyyyyy, Mar 24, 2021
    #1

  2. N8 certificates not trusted/don't match the name

    Well I worked out for myself how to verify the certificates are genuine:

    • Using a desktop computer
    • Go to the page with the certificates
    • Select a certificate
    • It will say either:
      • Certificate already exists - this confirms that the certificate on the website matches one already in your browser, which we already trust, therefore the certificate on the website is trustworthy
      • Asks if you want to install the certificate, DON'T.
        • First view the certificate details.
        • Copy the certificate serial number or SHA1/SHA256/MD5/etc hash
        • Paste this into a search engine
        • If another website that you trust lists the certificate, e.g. your phone manufacturer or another trusted website (preferably a secure website, therefore you have confidence the website is genuine), then you can trust the certificate
        • If no trustworthy sites are returned in the search then try another hash or serial number
        • If you can't find any trustworthy sites listing the certificate then I suggest you don't trust it.
    • Finally, if you decide you trust a certificate then you can download and install on your phone.
     
    CurvyClover488, Mar 24, 2021
    #2
  3. Can't disable Windows Hello for Business

    I receive this error in Event Viewer whenever I boot Windows 10 Pro version 1709 build 16299.309.

    Windows Hello for Business provisioning will not be launched.

    Device is AAD joined ( AADJ or DJ++ ): Not Tested

    User has logged on with AAD credentials: No

    Windows Hello for Business policy is enabled: Not Tested

    Local computer meets Windows hello for business hardware requirements: Not Tested

    User is not connected to the machine via Remote Desktop: Yes

    User certificate for on premise auth policy is enabled: Not Tested

    Machine is governed by none policy.

    See https://go.microsoft.com/fwlink/?linkid=832647 for more details.

    I tried the following suggestion:

    "Type gpedit.msc Go to Computer Configuration > Administrative Templates > Windows Components > Microsoft Passport for Work OR Windows Hello for Business Edit "Use Microsoft Passport for Work" OR "Use Windows Hello for Business" and set it to disabled."

    I checked the registry and \HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork Enabled is set to 0.

    I am using the Administrator account.

    The error continues at every bootup.

    Thank you.
     
    Ted Harris 600, Mar 24, 2021
    #3
  4. Windows hello for business on premise certification trust

    N8 certificates not trusted/don't match the name

    Hello,

    Thanks for the suggestion. How do you know that the certificates from this person are trustworthy? The web domain is just personal one, not from any trusted certificate authority.

    Thanks.
     
    CurvyClover488, Mar 24, 2021
    #4
Thema:

Windows hello for business on premise certification trust

Loading...
  1. Windows hello for business on premise certification trust - Similar Threads - hello business premise

  2. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows 10 Gaming
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  3. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows 10 Software and Apps
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  4. Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...

    in Windows Hello & Lockscreen
    Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what...: Hello,Today we have deployed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.We have understood that during the...
  5. Windows Hello For Business Cloud Trust

    in Windows Hello & Lockscreen
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  6. Windows Hello For Business Cloud Trust

    in Windows 10 Gaming
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  7. Windows Hello For Business Cloud Trust

    in Windows 10 Software and Apps
    Windows Hello For Business Cloud Trust: I am running into 2 issues that would love some clarity on:- 1 computer I am unable to setup a pin on. Keep getting the error during step up auth after entering my credentials to receive the 2fa prompt it fails with "Unable to get a token using the Web Account Manager. Error...
  8. Deploy Windows Hello for Business Cloud Trust using Intune

    in Windows Hello & Lockscreen
    Deploy Windows Hello for Business Cloud Trust using Intune: Hi,I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trustFirst I tried using GPO and it works well. I can see the event 358...
  9. Deploy Windows Hello for Business Cloud Trust using Intune

    in Windows 10 Software and Apps
    Deploy Windows Hello for Business Cloud Trust using Intune: Hi,I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trustFirst I tried using GPO and it works well. I can see the event 358...
  10. Windows Hello for Business key trust configuration with ADFS

    in Windows Hello & Lockscreen
    Windows Hello for Business key trust configuration with ADFS: I'm looking to implement windows hello for business key trust modern managed topology with an ADFS server so mitigate the AAD connect sync back to on premise to map the public key to the AD user attribute.Do you know what configurations in ADFS are required for this...