Is temporary access pass supported for Windows hello for business setup on Hybrid azure ad joined device ?

Global Admin- TechSpace 40 Reputation points
2023-09-01T06:58:06.9666667+00:00

I have set up tap policy on my test tenant. I have referred the Temporary Access pass settings Microsoft Document (https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-temporary-access-pass) regarding windows hello for business.

Is temporary access pass supported for Windows hello for business setup on Hybrid azure ad joined device ?

Please guide me in this issue as I am unable to find the relevant docs or link for the above query. Thanks in advance.

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Nagappan Veerappan 651 Reputation points Microsoft Employee
    2023-09-05T20:18:18.4566667+00:00

    HAADJ windows login methods are Password, PIN, BIO, FIDO2 at lock screen. Web sign-in only supported in AADJ. Hence when you don't have any other credentials. you are left with password login on windows HAADJ machine. Once you login during provisioning TAP can be used as MFA (second factor). No problem using TAP. It just that it can't be alone used as boot strap credentials you do on AADJ with Web sign-in.

    Hope this helps. Feel free to post if you have any other questions.

    Regards

    Nagappan V


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.