Hello
I see that you are experiencing a configuration issue with Windows Hello for Business on Windows Server 2016. Here are some steps and considerations that may help you resolve this issue:
Check Group Policy Settings: Ensure that the Group Policy settings for Windows Hello for Business are correctly configured. You mentioned that you have set "Use Windows Hello for Business" and "Use certificate for on-premises authentication." Double-check these settings to ensure they are applied correctly.
Hybrid vs. On-Premises Deployment: Windows Hello for Business can be deployed in different scenarios, including hybrid and on-premises. Make sure that your deployment scenario matches the configuration. For on-premises deployments, ensure that the necessary infrastructure, such as Active Directory and certificate services, is properly set up.
Certificate Trust vs. Key Trust: Windows Hello for Business supports both certificate trust and key trust models. Verify that the trust model you are using is correctly configured. Certificate trust requires a Public Key Infrastructure (PKI) to issue certificates to users.
Azure AD Integration: If your setup is prompting for a Microsoft account, it might be due to Azure AD integration. Ensure that the devices are correctly joined to your on-premises Active Directory and not inadvertently linked to Azure AD.
Review Deployment Guides: Refer to the deployment guides and documentation for Windows Hello for Business. The Microsoft Learn article on planning a Windows Hello for Business deployment provides detailed information on different topologies, architectures, and components.
Plan a Windows Hello for Business Deployment | Microsoft Learn
Troubleshooting Permissions: Check for any permission issues that might be causing the problem. For example, ensure that the necessary permissions are granted for the msDS-KeyCredentialLink attribute in Active Directory.
By following these steps, you should be able to identify and resolve the issue with your Windows Hello for Business setup on Windows Server 2016