Intune: Windows Hello for Business

Windows Hello for Business has been around for some time as an alternative sign-in method and it allows a user gesture to sign-in instead of just using a password. There are many sign-in gestures available and depending on what is supported based on the hardware, one can configure a PIN, biometric or a fingerprint. For corporate devices, PIN is the most suited method and it is easily configurable on Intune managed devices. However, I will cover other settings in this blog as well.

Now Windows Hello for Business is Not Configured by default. So, in case you do not want to enable it for all your users (Remember this setting is a tenant wide setting) then you will need to atleast configure it to Disable for Intune to be able to manage the feature.

 


Once in place, one can then deploy a Windows Identity protection profile policy to devices of your choice to enable the feature along with the desired configuration.

Let’s begin

  1. Browse to Devices – Windows – Configuration profile.
  2. Click Create Profile.
  3. Choose Windows 10 and later as Platform
  4. Select Identity Protection as Profile type
  5. Click Create
  6. Give a name
  7. Configure Windows Hello for Business: Enable
  8. Minimum PIN length: <Minimum is 6, but you can enforce a lower value>
  9. Maximum PIN length: <Maximum length is 127 characters>
  10. Lowercase letters in PIN: Allowed
  11. Uppercase letters in PIN: Allowed
  12. Special characters in PIN: Allowed
  13. PIN expiration (days): <Default is 41 days>
  14. Remember PIN history: <Default is 5 reused>
  15. Enable PIN recovery: Enable
  16. Use a Trusted Platform Module (TPM): <You can enable this, I left it out for testing purposes>
  17. Allow biometric authentication: Enable
  18. Use enhanced anti-spoofing, when available: Enable
  19. Certificate for on-premise resources: Enable
  20. Use security keys for sign-in: Enable (This setting is available for Windows 10 1903 and later.)
  21. Assign it to a user or a device group.


User Experience

After a device has checked in with Intune, Windows Hello setup screen should show up in 15-20 minutes. If it doesn’t then it most certainly will show up after a reboot.

 


If you haven’t already confirmed your identity on the device, you’ll be prompted to do so. Once done, you should receive a text code.

 





User will be able to login using the newly setup PIN.

 




 

Comments

Popular posts from this blog

How to force escrowing of BitLocker recovery keys using Intune

Intune: Configure Printers for Non-Administrative Users

Intune: UAC Elevation Prompt Behavior for Standard Users