windows-hello
Windows Hello for Business
Windows Hello for Business (WHfB) replaces passwords on Windows with a phishing-resistant 2-factor credential: a PIN or biometric (something you know/are) that unlocks a per-device asymmetric key (something you have, bound to TPM). The credential never leaves the device and is not replayable.
When to use
Eliminating password sign-in on Windows endpoints and meeting phishing-resistant MFA requirements for users on Windows. Use this skill to choose the trust model, satisfy prerequisites, and roll out provisioning.
Do not use this skill for FIDO2 keys on shared devices (entra-id), CA policy
(conditional-access-mfa), or device compliance (intune-device-mgmt).
Pick the trust model
WHfB has three trust models. The choice depends on whether on-prem AD SSO is needed and the state of the AD environment.