Forum Discussion
Login Options for Windows Hello
Yes, once you deploy Windows Hello for Business, the user will see additional login credential provides such as PIN, fingerprint, and/or Facial recognition depending on the hardware and if the user enrolled biometrics.
Mike
Yes of course, let me clearify:
When will we be able to demand, for instance, both Facial recognition AND a PIN/Password to login?
- Mike StephensJun 21, 2017Brass Contributor
Great question. Windows Hello for Business currently is two factor authentication-- something you have ( a private key protected by the TPM) and, something you have (PIN) or something part of you (Bio). We are investigating multi-factor authentication (all three factors), but no time line has been established.
What would be interesting to know is what business requirement does three factors authentication satisfy in your organization that two factors do not?
Mike
- Stephen HoganJun 21, 2017Iron Contributor
Remotely accessing another system - say an RDP session to a node on a customer site.
The third-factor could be session based, as in it;s only needed for the task the user is running it for,
- Mike StephensJun 21, 2017Brass ContributorWindows Hello for Business has a smart card emulation that enables you to use it with RDP smart card redirection. That scenario should work today. You cannot enroll Windows Hello for Business on a remote computer because you do not actually possess the "the something you have" Authentication factors are well defined-- something you have, something you know, or something part of you. A session token is something you have, which would duplicate the protected private key. We need to use a factor from a different category. - Mike
- Todd GodchauxJun 21, 2017Brass ContributorI'm assuming there'll be controls on each MFA method? For instance in a secure area we don't want camera's turning on but still would like to use WHFB.
- Mike StephensJun 21, 2017Brass ContributorThere is a Group Policy setting to enable/disable biometrics in conjunction with Windows Hello for Business. - Mike
- AnonymousJun 21, 2017
Well its partly due to travels and for instance customs. Alot of countries got different rules on this subject, so having just facial recognition might not be the best idea.