Migrating from Windows Hello for Business Certificate Trust to Cloud Kerberos Trust, what about the decommissioning of the AD FS?

Florian BUSSIERE 10 Reputation points
2023-12-11T08:41:15.1033333+00:00

Hello,

Today we have deloyed Windows Hello for Business to all our end user Windows 10 devices based on the "Certificate Trust" deployment. We have now prepared, configured and tested with success the "Cloud Kerberos trust" deployment.

We have understood that during the migration from the on-premise deployment to the hybrid deployment, we have to force users to re-enrolle them with Windows Hello for Business. Please correct me if I am wrong.

Now we are wondering, what would be the impact if we decomission the AD FS before having redeployed all our users to the hybrid scenario "Cloud Kerberos Trust"?

For users not migration to the hybrid deployement, will WHFB still work without AD FS? What will happen if the certificate delivered by the internal certificate authority get expired? Will the certificate still be renewed by the PKI, without going through the AD FS? Or will the user get stuck, with a none working PIN? Thanks.

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,259 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,907 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.