Deploy Windows Hello for Business Cloud Trust using Intune

Toni Martínez 106 Reputation points
2022-09-20T10:51:40.927+00:00

Hi,

I am deploying WHfB Cloud Trust in Hybrid Azure AD. I followed the Microsoft Documentation: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trust

First I tried using GPO and it works well. I can see the event 358 saying WHfB cloud trust is enabled and the computer got the TGT ticket. Everything works fine.

But then I removed the GPO and tried using Intune. The users are prompted to create the PIN and they are able to log in but it fails randomly. I checked the event viewer and now in the event 358 it says that Cloud Trust is not enabled and the TGT ticket is "not tested"

Both the configuration profiles in Intune (enablement with OMA uri and PIN Reqs) are applied, the state is "Succeded" for the computers. Why is Cloud Trust not enabled? I guess everything is ok in AD and the computer as when I enable the GPO it works fine and I can see how the secret is stored and read in Azure AD. Thanks

Regards.

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,748 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,713 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,428 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Givary-MSFT 27,566 Reputation points Microsoft Employee
    2022-09-21T06:46:55.65+00:00

    @Toni Martínez

    As I understand you are deploying Windows Hello for Business Cloud Trust using Intune. Users log in fails randomly.

    The Not Tested state is reported if cloud Kerberos trust is not being enforced by policy or if the device is Azure AD joined.

    Reference: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-kerberos-trust?tabs=intune#:~:text=The%20Not%20Tested%20state%20is%20reported%20if%20cloud%20Kerberos%20trust%20is%20not%20being%20enforced%20by%20policy%20or%20if%20the%20device%20is%20Azure%20AD%20joined.

    Also help me with the output of klist cloud_debug to investigate further.

    Let me know if you have any further questions.