Forum Discussion
AndrewManning
May 21, 2020Copper Contributor
Windows Hello enforces 2FA
In a school environment we want to use Windows Hello. If I disable it, all users can sign into AzureAD managed devices easily. However they cannot enable Windows Hello (face) If I enable Win...
AndrewManning
May 23, 2020Copper Contributor
Windows Hello doesn’t require 2FA on a Windows domain, so why does it require it when the device is managed by Intune?
All of our Students are under 11 years old. I do not think that expecting them to have a mobile is really acceptable.
All of our Students are under 11 years old. I do not think that expecting them to have a mobile is really acceptable.
Thijs Lecomte
May 23, 2020Bronze Contributor
There is a big difference between Windows Hello and Windows Hello for Business
Check out this article for more info: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview
Check out this article for more info: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview
- AndrewManningMay 23, 2020Copper ContributorSo can we enable Windows Hello on devices, rather than Windows Hello for Business via Intune?
- Thijs LecomteMay 23, 2020Bronze ContributorAFAIK, there is no way to do this
- AndrewManningMay 23, 2020Copper Contributor
In Device Restriction profile there is one called "Windows Hello device authentication" (it does not mention Business).
I wonder if this would allow it?
I would need to do some testing first