Windows Hello for Business - That option is temporarily unavailable

Sysadmin 1 Reputation point
2022-02-15T07:47:03.04+00:00

Hi there,

I have just set up windows hello for business. Iam enrolling windows devices via GPO and applying windows hello configuration via a profile in endpoint manager.
Prompt for configuration comes directly upon windows logon.
Firstly i tried it on my PC and it went great, i can successfully login with either PIN or fingerprint.

Problem then comes with some users who get the message on the lockscreen "That option is temporarily unavailable. For now, please use a different method to sign in".
Iam really stuck and cant really find a explanation on why it works on mine but not on others users. I have checked groups, MEM profiles and GPO settings, the settings are identical.
Can it be some local releated issue, some setting that is missing or different within windows.

This happens both on win 11 and win 10.

Thanks

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,793 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,767 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,274 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,732 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,258 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 39,391 Reputation points
    2022-02-16T11:00:24.943+00:00

    Hello @Sysadmin

    This is likely due to a lack of permissions for the account to write back to Active Directory.

    For the specific users access ADUC console then:

    1. make sure Advance Features are enabled in View
    2. go to user properties –>
    3. Security tab –> Advanced button
    4. Select the check box “to include inheritable permissions from this object’s parent”
    5. Save and ask the user to retry the operation

    Hope this helps with your query,

    --
    --If the reply is helpful, please Upvote and Accept as answer--

    2 people found this answer helpful.

  2. Reza-Ameri 16,836 Reputation points
    2022-02-16T16:18:04.587+00:00

    Just for test perform Clean Boot and see if the problem persist?
    Take a look at:
    https://support.microsoft.com/en-us/topic/how-to-perform-a-clean-boot-in-windows-da2f9573-6eec-00ad-2f8a-a97a1807f3dd
    Try open start and search for feedback and open the Feedback Hub app and report this issue.