Forum Discussion
Logging on to Remote Desktop using Windows Hello for Business & Biometrics
- Oct 03, 2018
Although late, we have published information around WHfB with RDP :
- FriskySpider29347654Dec 21, 2021Copper Contributor
BusinessFish Bro that sounds good (using NDES to get certs synced with Intune) do you have any instructions?
- Anders GidlundFeb 16, 2021Copper Contributor
- Matthew_PalkoFeb 24, 2021
Microsoft
Anders Gidlund you can follow the guide for using certificates with Azure AD Joined devices to enable SSO with Windows Hello for Business to on-prem (Using Certificates for AADJ On-premises Single-sign On single sign-on - Microsoft 365 Security | Microsoft Docs). For Azure AD Joined devices, AD FS cannot be used as a certificate RA so Intune and NDES have to be used to distribute certs. The method isn't unique to Azure AD Join and can be done with any modern managed device.
- Anders GidlundMar 04, 2021Copper Contributor
Matthew_Palko sorry If I am dumb, but I just want to make this clear.
Im setting up a Key Trust because I do not and cannot use ADFS in our environment. Youre referring to a guide for a Certificate Trust setup.
Im using these guides:
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-key-trust
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-key-whfb-settings-pki
Do you mean that I can setup a Key Trust deployment without ADFS and then just install NDES like in the guide your linking to (starting from here: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert#install-and-configure-the-ndes-role) and then have functionality to login using WHfB to on-premises RDS servers?