Windows Hello for Business should be configured where applicable
PreviousEncryption shall be required on all devicesNextAuthorized Applications should be deployed to managed devices
Last updated
Last updated
For Windows 10/11 devices, use of Windows Hello for Business replaces the use of passwords with strong two-factor authentication on devices. This authentication consists of a user credential that’s tied to a device and uses a biometric or PIN.
Windows Hello for Business should be configured where applicable
• Any tenant with Intune licensing can access this setting.
Configure Windows Hello at the time of enrollment:
Configure Windows Hello after device enrollment:
Users will be prompted to set up facial recognition or fingerprint depending on the device. Users will also be asked to establish a pin in case that biometric authentication fails or cannot be accessed.