Windows Hello for Business Cloud Trust and Windows 11 Passkey feature

Woody Chiu at RASI 226 Reputation points
2023-09-23T19:13:26.54+00:00

Our company already successfully implemented SSO Passwordless Sign-on with Windows Hello for Business Cloud Trust. During that implementation, there was a Kerberos AD RODC object created, and Active Directory Connector was all set up accordingly.

We are now looking to implement the Windows 11 "Passkey" feature on top of the PIN, Biometric, and FIDO Security Key that they are already in use. Is there a new Kerberos AD Server object that needs to be created or we can continue to rely on the previous object we created to implement the "Passkey"?

Appreciated.

WC

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Windows for business | Windows Client for IT Pros | User experience | Other
Microsoft Security | Intune | Other
Microsoft Security | Microsoft Entra | Other
0 comments No comments
{count} votes

Accepted answer
  1. Brian Zarb 1,685 Reputation points
    2023-09-23T20:03:22.17+00:00

    since you already have Windows Hello for Business Cloud Trust and related Kerberos AD RODC objects set up, you've got a good foundation for additional authentication features.

    Compatibility with Existing Kerberos AD RODC Object Typically, the Win 11 Passkey feature would work in conjunction with your existing Azure Active Directory and Intune configurations. Since you already have a Kerberos AD RODC object and Active Directory Connector set up for Windows Hello for Business, it's likely that you can continue to rely on these existing objects for implementing the Passkey feature.

    I'd still recommend documenting and testing in a controlled environment, hope this helps!

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Givary-MSFT 35,626 Reputation points Microsoft Employee Moderator
    2023-09-26T10:40:39.5133333+00:00

    @Woody Chiu at RASI Thank you for reaching out to us, there is no need to create another Azure Kerberos AD Server object again, passkeys work along with existing Windows Hello configuration which you have already.

    Reference: https://support.microsoft.com/en-us/windows/passkeys-in-windows-301c8944-5ea2-452b-9886-97e4d2ef4422

    Let me know if you have any further questions, feel free to post back.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.