Windows Hello For Business through Cloud Kerberos Trust working inconsistently

Elijah Karnes 0 Reputation points
2024-09-19T17:22:46.09+00:00

We have an Azure AD Connect setup and have configured Windows Hello for Business with Cloud Kerberos trust. In initial testing with a half dozen users all but one have worked correctly. One specific user gets the following event on any computer we have tested with them so far:Windows Hello for Business provisioning will not be launched.

Device is AAD joined ( AADJ or DJ++ ): Not Tested

User has logged on with AAD credentials: No

Windows Hello for Business policy is enabled: Not Tested

Windows Hello for Business post-logon provisioning is enabled: Not Tested

Local computer meets Windows hello for business hardware requirements: Not Tested

User is not connected to the machine via Remote Desktop: Yes

User certificate for on premise auth policy is enabled: Not Tested

Machine is governed by none policy.

Cloud trust for on premise auth policy is enabled: Not Tested

User account has Cloud TGT: Not Tested

See https://go.microsoft.com/fwlink/?linkid=832647 for more details.

This user has the exact same setup as all the other users, the policy is showing as applied to their account through gpresult. They are correctly synced to their 365 environment and SSO works on computers they sign into. I have tried to find any details about this Event but basically all answers I have seen are about disabling WHfB to get rid of the error which is obviously not what I am going for here. Any assistance is much appreciated.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,498 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,116 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.