Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what about the decommissioning of the AD FS?
Hello,
Today we have deloyed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.
We have understood that during the migration from the on-premise deployment to the hybrid deployment, we have to force users to re-enrolle them with Windows Hello for Business. Please correct me if I am wrong.
Now we are wondering, what would be the impact if we decomission the AD FS before having redeployed all our users to the hybrid scenario "Cloud Kerberos Trust"?
For users not migration to the hybrid deployement, will WHFB still work without AD FS? What will happen if the certificate delivered by the internal certificate authority get expired? Will the certificate still be renewed by the PKI, without going through the AD FS? Or will the user get stuck, with a none working PIN? Thanks.