@Nicholas Wirth Thank you for following up on this and I'm glad that you were able to resolve your issue!
Thank you for also sharing your solution so that others experiencing the same thing can easily reference this. Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others", I'll repost your solution in case you'd like to accept the answer.
Error Message:
We can't sign you in with this credential because your domain isn't available. Make sure your device is connected to your org's network and try again. If you previously signed in on this device with another credential, you can sign in with that credential.
Issue:
You're implementing Windows Hello for Business cloud Kerberos trust so your users can use WHFB to access local resources. However, when trying to login you're running into the error message above and when modifying the
msDS-NeverRevealGroup
property you're still unable to login.
Solution:
The issue ended up being your 2012R2 server having all master roles. As soon as the roles were transferred to your 2022 server everything started working as expected.
If I missed anything please let me know and I'd be happy to add it to my answer, or feel free to comment below with any additional information.
I hope this helps!
If you have any other questions, please let me know. Thank you again for your time and patience throughout this issue.