Forum Discussion

PaulM1405's avatar
PaulM1405
Copper Contributor
Aug 29, 2024
Solved

WHfB prompting for password at first login

Hi All,

 

I can't seem to get these Intune policies correct for WHfB (Windows Hello for Business)

 

I want WHfB active using a pin for a customer. I have a test VM setup and registered with WHfB correctly. When you first power on the machine and login, there is no prompt for a pin, only the M365 password. Once logged in, I can lock, or log off and I am prompted with the PIN login. I restart the VM and I am pack to having to use a password for the initial login.

I have WHfB setup in the following areas

  • Endpoint security | Account protection (Assigned to All devices and All users)
    • Use Windows Hello for Business (Device) - True
    • Use Windows Hello for Business (User) - True (tried without this first)
    • Minimum PIN length - 6
  • Devices | Enrollment
    • Configure Windows Hello for Business - Enabled
    • TPM - Preferred
    • Minimum PIN length - 6
    • Allow biometric - Yes
    • Allow phone sign-in - Yes
  • Devices | Configuration (assigned to All users & All devices)
    • Turn on convenience PIN sign-in - Enabled
    • Minimum PIN Length (User) - 6
    • Use Windows Hello For Business (User) - True
    • Use Remote Passport - Enabled
    • Allow Use of Biometrics - True

 

I know there is quite some double up having this configured at all possible levels. I started with Device enrollment and a configuration profile, and then moved to Account protection.

I'm currently going round in circles trying to work out why the initial login isn't prompting for a PIN.

(I also built a new VM and it's doing the same thing). Although, first reboot it worked fine from memory.

Thanks in advance Guru's

  • Problem solved. I was using HyperV for testing. The session mode was set to basic. As soon as I changed it to an enhanced session the PIN worked as expected.

3 Replies

  • PaulM1405's avatar
    PaulM1405
    Copper Contributor
    Problem solved. I was using HyperV for testing. The session mode was set to basic. As soon as I changed it to an enhanced session the PIN worked as expected.
  • NicklasOlsen's avatar
    NicklasOlsen
    Iron Contributor
    Hi,

    To start off with, can we try to start with configuring it only in one place?
    Currently, I have the default WHFB settings enabled under enrollments, without any changes. I get prompted to setup PIN on the initial sign-in.

    Could it be possible to test with WHFB configured in only one place?
    • PaulM1405's avatar
      PaulM1405
      Copper Contributor

      NicklasOlsen, I am prompted to setup the PIN. It's after a reboot it requests the password without any prompt to enter or select the option to enter the PIN.

      Logging off or locking the VM, once already logged in prompts for the PIN every time

       

      I have disabled the other methods in Intune to see if it makes any difference.

Resources