Usage of Windows Hello for Business for Passwordless MFA

Quentin LELONG 0 Points de réputation
2025-03-07T15:16:25.0833333+00:00

Hello,

Using Hybrid AD / EntraID, I try to use Windows Hello for Business to enable MFA / Strong authentication and I have an issue with Conditional Access Policies about it.

For context, I deployed Windows Hello for Business on our computers with GPO, and we can use it to authenticate on Windows and also on cloud apps like Office portal.

What I want to do is to be able to login only with a Passwordless MFA solution, to disable email/password auth. So i configured the Grant control like this :
Image de l’utilisateur

When i try the policy for a test user, it works :
Image de l’utilisateur

But looking at the conditions of the Passwordless MFA, it shows that WHfB isn't registered for the user :
Image de l’utilisateur

And in the User's authentication methods, there is WHfB and it is working if we use it to authenticate on Windows or any cloud app (Office Portal for example) :
Image de l’utilisateur

Is this possible at all ? I looked at many docs from Microsoft and think the setup and configuration are correct, I have no clues left.

Thank you in advance.

Regards,

Azure
Azure
Plateforme et infrastructure de cloud computing pour la génération, le déploiement et la gestion d’applications et de services à travers un réseau mondial de centres de données gérés par Microsoft.
426 questions
{count} votes

Votre réponse

Les réponses peuvent être marquées comme réponses acceptées par l’auteur de la question, ce qui aide les utilisateurs à savoir que la réponse a résolu le problème de l’auteur.