windows-hello

Installation
SKILL.md

Windows Hello for Business

Windows Hello for Business (WHfB) replaces passwords on Windows with a phishing-resistant 2-factor credential: a PIN or biometric (something you know/are) that unlocks a per-device asymmetric key (something you have, bound to TPM). The credential never leaves the device and is not replayable.

When to use

Eliminating password sign-in on Windows endpoints and meeting phishing-resistant MFA requirements for users on Windows. Use this skill to choose the trust model, satisfy prerequisites, and roll out provisioning.

Do not use this skill for FIDO2 keys on shared devices (entra-id), CA policy (conditional-access-mfa), or device compliance (intune-device-mgmt).

Pick the trust model

WHfB has three trust models. The choice depends on whether on-prem AD SSO is needed and the state of the AD environment.

Installs
74
GitHub Stars
173
First Seen
Jun 10, 2026
windows-hello — vinayaklatthe/microsoft-security-skills