Difference in Windows Hello settings in Device Enrollment and through Configuration Policy

Mountain Pond 1,411 Reputation points
2024-07-02T22:49:25.6833333+00:00

Hello, what is the difference between configuring Windows Hello in the Device Enrollment stack and through Configuration Policy.

As far as I understand, only that the policy can be applied to devices. And Enrollemt will be applied to users, no matter what device it runs on, i.e. at the organizational level.

msedge_s0xMQulQ73

msedge_JwKtIYAJ0d

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,787 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,307 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,674 questions
0 comments No comments
{count} votes

Accepted answer
  1. ZhoumingDuan-MSFT 10,730 Reputation points Microsoft Vendor
    2024-07-03T01:44:00.8833333+00:00

    @Mountain Pond,Thanks for posting in Q&A.

    From your description, I know you want to know the difference in Windows Hello settings in Device Enrollment and through Configuration Policy.

    Based on my research, here are some differences between Windows Hello settings in Device Enrollment and through Configuration Policy.

    1.Windows Hello for Business settings in Device enrollment is only available during device enroll in Intune and also support Windows Autopilot out-of-box-experience, but Windows Hello for Business through configuration policy is available after device enrollment.

    2.Windows Hello for Business settings in Device enrollment is available for All users which means it will apply to your entire organization, but Windows Hello for Business through configuration policy available for both devices group and users' group. When you assign it to device group, all users get prompt to configure WHfB at first-time log on to the device, if you assign it to user group, the targeted user didn’t get WHfB prompt at first log on, until the WHfB policy is synced.

    https://learn.microsoft.com/en-us/mem/intune/protect/windows-hello?WT.mc_id=Portal-Microsoft_Intune_Enrollment#create-a-windows-hello-for-business-policy

    https://learn.microsoft.com/en-us/mem/intune/protect/identity-protection-configure

    https://msendpointmgr.com/2022/09/04/manage-windows-hello-for-business-whfb-with-intune/

    Non-official, just for reference.

    Hope above information can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

0 additional answers

Sort by: Most helpful