Windows Hello for Business in Hybrid Environment - 'Not Applicable' Error

Wakeyo Tolera Ejeta 0 Reputation points
2024-04-23T09:29:26.71+00:00

I am trying to deploy WHfB in a hybrid environment where devices are being managed by both SCCM and Intune.

After I created Identity Protection Configuration on Intune that requires WHfB, I got an error that says "Not Applicable".

Note: Since we have implemented MFA using Conditional Access Policy, we have implemented the requirements for WHfB regarding the WHfB GPO, Auto-MDM enrollment GPO, and Hybrid Azure AD Join.

When I research one of the reasons that this happens is if the device configuration role on SCCM is assigned to Configuration Manager for co-managed devices.

When I check, this is right. The "Device Configuration" is assigned to Configuration Manager on SCCM. To solve this, I tried changing the workload for 'Device Configuration' from Configuration Manager to Intune, but the 'Device Protection' workload also changes at the same time. And I don't want 'Device Protection' workload to change while I try to change the 'device configuration' workload because we manage defender using SCCM.

How can I solve this and implement WHfB successfully?

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
435 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,923 questions
Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
169 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,207 questions
Microsoft Configuration Manager
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. glebgreenspan 2,240 Reputation points
    2024-04-23T12:13:08.0533333+00:00

    Hello Wakeyo

    Make sure you done these steps:

    1. Confirm that the Identity Protection Configuration in Intune is correctly configured to require Windows Hello for Business.
    2. Verify that the WHfB GPO and Auto-MDM enrollment GPO have been successfully applied to the devices in your environment.
    3. Check the configuration of the Conditional Access Policy for MFA to ensure that it is not conflicting with the WHfB requirements.
    4. Make sure that the device configuration role in SCCM is not assigned to Configuration Manager for co-managed devices. If it is, try changing the workload for 'Device Configuration' to Intune. If changing the workload affects other configurations that you do not want to change, you may need to consider adjusting your device management strategy to accommodate both platforms.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.