Windows Hello For Business - Elevate to domain admin

Darren Moore 0 Reputation points
2024-04-09T14:57:04.0833333+00:00

I have recently implemented Windows Hello for Business on a couple of test users.  I have deployed via a GPO and have a hybrid environment using Entra kerberos. I require two factors for authentication with the following options: pin, face, fingerprint and while on prem a trusted network takes the place as the second factor. I want to move to a pass wordless environment, and require WHFB to login, (policy Interactive login, Require Windows Hello for Business or smart card).  The question I have is, how do you run an administrative task if you cannot use passwords, to elevate to a domain admin when a task is required? With this policy enabled, I cannot use my domain admin user, do I have something reconfigured?  I dont want to allow a password to login , that defeats the purpose of the 2 factors.  But obviously I need to use a domain admin account on occasion.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,160 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,886 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,193 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2024-04-09T14:57:04.1+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Windows Hello for Business is a two-factor authentication method that replaces passwords with a strong credential that enables easy two-factor authentication. When the policy "Interactive login, Require Windows Hello for Business or smart card" is enabled, users are required to use Windows Hello for Business or a smart card to log in. However, if you need to run an administrative task that requires domain admin privileges, you can use the "Run as different user" option to run the task as a domain admin. This option allows you to enter the credentials of a domain admin account to run the task with the necessary privileges.

    References:

    0 comments No comments