Article Intended For
Penn State IT Staff.
Introduction
Windows Hello for Business is a feature of Microsoft's Azure Active Directory and Microsoft Multifactor Authentication. It is considered a passwordless phishing resistant strong authentication method. It is approved for use with ATOs and Windows bound Enterprise Active Directory systems. This does enable PIN, Fingerprint and Facial Recognition
Requirements:
- Windows 11 and 10 version 1703 or later, Server 2016 or later.
- Windows machine must be bound to the University Enterprise Active Directory
- An Enterprise Active Directory security group you will use to assign policies to the computer to enable Windows Hello for use.
- An Enterprise Active Directory security group you will use to enable the user to use Windows Hello for device logon.
- Is Hybrid Joined, If unsure or need to request hybrid join, follow this link to Hybrid Join ServiceNOW KB here.
- Machine MUST stay connected to the Global Protect VPN during this entire setup and configuration and must periodically connect to global protect or access could be lost.
- Facial Recognition requires a camera to setup and authenticate.
- Fingerprint Recognition requires a Fingerprint reader.
Step-by-Step Instructions
- Submit a request to WebSSO team to leverage Windows Hello for Business for Sign-In WebSSO general request form. Select Windows Hello for Business.
- Provide the User and Computer EAD security groups that should already exist. If not you will need to create these defined above.
- You will receive a response that the groups have been added to the appropriate GPOs
- Please allow 1 full day for the policies to fully apply to the computer
User Directions: These are generally for IT staff reference.
- Login into your Windows Desktop or Laptop system normally with username and password
- Connect to the global protect VPN and verify it is connected.
- Select the Windows Start menu and type "Sign-In Options"
- Click or select Sign-In Options to launch the Sign-In Options control panel.
- Select the Windows Hello Sign In Option you wish to leverage and that is supported by your system. Some systems do not support Facial recognition, or Fingerprint or PIN without additional components. Please check with your IT staff if you wish to leverage a non-working method on your system
Facial Recognition setup:
- Select Facial recognition (Windows Hello)
- Select Setup
- Select Get Started
- Verify your identity with your authentication credentials, our example uses username and password.
- Your configured default camera will capture your facial recognition.
- Once completed you will come to the end of the setup, You can choose to improve recognition or select close.
- Once configured, to cache your windows hello for business sign in to use when off the any network on your device.
- Verify you are still connected to the Global Protect VPN
- Select the start menu.
- Select your user ICON and the option to switch users.
- Select to Sign In PIN option.
- Provide your Windows Hello for Business PIN
- This will cache your windows hello for business PIN for offline sign ins.
Fingerprint recognition setup:
- Select Fingerprint recognition (Windows Hello)
- Select setup, a dialog box will popup "Windows Hello Setup
- Select Get Started
- Verify your identity with your authentication credentials, our example uses username and password.
- Scan your fingerprint.
- Once scanned you will receive a message, "All set!".
- Select Close
- Once configured, to cache your windows hello for business sign in to use when off the any network on your device.
- Verify you are still connected to the Global Protect VPN
- Select the start menu.
- Select your user ICON and the option to switch users.
- Select to Sign In PIN option.
- Provide your Windows Hello for Business PIN
- This will cache your windows hello for business PIN for offline sign ins.
PIN setup:
- Select PIN (Windows Hello).
- Select Setup.
- Verify your identity with your authentication credentials, our example uses username and password.
- Set up a PIN. Select the Blue Option PIN requirements to verify you are following the University security requirements for PIN complexity or you will receive an error.
- You will be directed back to the Sign in options screen.
- Once configured, to cache your windows hello for business sign in to use when off the any network on your device.
- Verify you are still connected to the Global Protect VPN
- Select the start menu.
- Select your user ICON and the option to switch users.
- Select to Sign In PIN option.
- Provide your Windows Hello for Business PIN
- This will cache your windows hello for business PIN for offline sign ins.
Known Errors:
PIN setup error: Provide a PIN that meets the complexity requirements. Your PIN must include at the following.