Windows Hello in Conditional Access Rule?

CharlesP 56 Reputation points
2022-10-31T16:01:26.087+00:00

I'm reading through the documentation on Authentication Strengths within the Conditional Access rules.

https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-strengths

I notice they list Windows Hello as one of the authentication methods that meets the Phishing Resistant MFA strength. I'm confused though, because it's still not supported (to my knowledge) to sign into Azure with Windows Hello? So how can this be used as a Conditional Access criteria.

Can someone fill me in?

Microsoft Security Microsoft Entra Microsoft Entra ID
{count} vote

2 answers

Sort by: Most helpful
  1. James Hamil 27,211 Reputation points Microsoft Employee Moderator
    2022-11-01T22:16:05.177+00:00

    Hi @CharlesP , thanks for your question and detailed information. Correct me if I misunderstand, but I think your confusion relates to the type of authentication that Windows Hello provides. For example, you use Windows Hello in place of a password, so you'll still be prompted for another MFA method. So for your usecase of the fingerprint, that's only being registered as one authentication method. The authenticator app is the other.

    To confirm, you're wishing to use Windows Hello as the second method after say, inputting a password?

    Please let me know if this explanation makes sense. If so I'll help you configure conditional access.

    Best,
    James


  2. Andreas Keller 0 Reputation points
    2024-03-08T21:06:00.5966667+00:00

    Hi, I‘m also confused by this. In my case the device is Entra joined & signed in via hello for business.

    If CA requires mfa, no prompt for hello, Entra insists on enrollment of Authenticator app.

    If CA is set to authentication strength Windows hello, it fails with CA message „you can’t get there from here“ and CA log states the required method was not available …

    best regards

    Andreas

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.