A cloud-based identity and access management service for securing user authentication and resource access
Thanks @Marilee Turscak-MSFT
I had read that page also along with other pages in the doc. and that is why I am thinking it is conflicting with other pages.
OR
https://interopevents.blob.core.windows.net/
there is NO mention of device authentication just for CERTIFICATE creation.
Of course if your are interested in ePRT, you definitely need the device-public-key in on-premAD
Besides, if at all device-public-key is needed for User-CERTIFICATE creation, then device-synchronization must happen before WHfB provisioning starts.
This will break the whole cert-trust model which can be accomplished synchronously as device will get the
user-key-receipt to proceed cert-creation and need NOT wait for the user writeback.
There is no such mention of device-key-receipt etc.
Have you practically did this setup and got failure without device writeback ? OR your input is based on documentation.