which way is best recommended for Windows Hello for Business from Intune?

SMF 25 Reputation points
2024-07-28T16:33:16.0333333+00:00

Hello,

It seems very confusing when Microsoft has no clear direction for how to create Windows Hello for Business deployment profile from Intune. Below article describes that Identity protection method for Hello is deprecated.

https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy

Now as per my understanding there are currently at least 4 methods which i am aware of are available.

Question 1 is, which one is recommended/best?

1- Using System Catalog

2- Using Custom CSP profile

3- Identity Protection

4- Account Protection

5-Global Windows Hello(lets way we disabled it and want to use targeted group of computers, so which of above is clear direction).

**Question 2:**Also, i faced issue when Disabled using Identity Protection for all, then enabled using System Catalog, policy wasn't enabling, any one has any idea on this too?, though enable using Identity Protection Config profile does work but Microsoft is deprecating that method

thanks

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,202 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,196 Reputation points MVP
    2024-07-28T16:57:53.16+00:00

    Depends on the requirements, but in most cases, it is Account Protection for me. Have a look at this which discusses the various options.

    https://rahuljindalmyit.blogspot.com/2021/04/how-to-block-windows-hello-for-business.html


  2. ZhoumingDuan-MSFT 13,735 Reputation points Microsoft Vendor
    2024-07-29T06:36:47.9+00:00

    @SMF, Thanks for posting in Q&A.

    Q1: Based on my research, the recommended method for deploying Windows Hello for Business is using the Account Protection policy. This method is part of the endpoint security policies in Intune and is designed to manage Windows Hello settings effectively.

    https://msendpointmgr.com/2022/09/04/manage-windows-hello-for-business-whfb-with-intune/

    Non-official, just for reference.

    Q2: Since you are using Account Protection to disable WHfB and System Catalog to enable WHfB, the policies created in these two different ways will cause a conflict that will invalidate the WHfB-enabled policy you created using System Catalog, it is recommended that you delete the WHfB policy created using Identity Protection (both the enable and disable policies), and then re-create a new WHfB policy using Account Protection. We recommend that you delete the WHfB policy created using Identity Protection (both enabled and disabled policies) and re-create a new WHfB policy using Account Protection.

    Hope this can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.