How to join Windows 10/11 Pro computer to Azure AD with passwordless authentication?

alippiatt 1 Reputation point
2022-05-26T15:09:09.047+00:00

We implemented passwordless authentication in our Azure AD environment and use Windows 10 and 11 Pro in our computers. When joining a computer to Azure Active Directory for the first time, the only option presented to a user is to provide their Azure AD username and password. Since we reset all of the passwords to something nobody knows, it seems Microsoft requires a password to join Windows 10/11 computers to Azure AD.

Then even AFTER joining, the user still needs their password the first time they login. Subsequently, any new users who attempt to login to the computer using their Azure AD credentials ALSO need their password, because it only asks them to setup Windows Hello for Business AFTER they login the first time.

The work-around I use right now is to reset their password, have them login, change it, then setup Windows Hello for Business. Not a good solution as this requires intervention and a lot of steps.

So, how can we completely eliminate passwords in this scenario?

Windows 10 Setup
Windows 10 Setup
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Setup: The procedures involved in preparing a software program or application to operate within a computer or mobile device.
1,918 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,783 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,657 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
20,320 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2022-06-10T19:04:21.607+00:00

    First, note that this really has nothing to do with Intune but is AAD specific.

    Today, there is no direct passwordless path for initial Windows AADJ, however, Temporary Access Password (https://video2.skills-academy.com/en-us/azure/active-directory/authentication/howto-authentication-temporary-access-pass) is planned to be enabled during Windows OOBE in the near future.

    1 person found this answer helpful.