Forum Discussion
Marc_Laf
Apr 14, 2023Iron Contributor
Azure AD Joined device is not honoring Windows Hello for Business Config Policy from Intune
With the availability of Cloud Kerberos Trust we are now able to deploy WHfB to our Hybrid workforce but we do have a handful of Azure AD Joined devices that we also need to deploy to, all of these d...
rahuljindal
Apr 15, 2023Bronze Contributor
Do you have the tenant wide WHfB feature enabled in Intune by any chance?
- Marc_LafApr 15, 2023Iron Contributor
The one under Device Enrollment? If so, it's Disabled and the rest of the settings match the policy I set. I only thought this one came into play during out of box setup (ie, enrollment) and is the lowest priority so other policies can overwrite it.
- rahuljindalApr 15, 2023Bronze ContributorSeems about right. I personally never used settings catalog to configure WHfB policies. Either used endpoint security account protection profile or device configuration identity protection profile. Each have their own pros and cons.
- Marc_LafApr 15, 2023Iron ContributorI still haven’t figured out the pros and cons to each despite writing out the differences. I have also tried setting the configuration through all methods and the results are the same. The device ignores what is set.