Usage of Windows Hello for Business for Passwordless MFA
Hello,
Using Hybrid AD / EntraID, I try to use Windows Hello for Business to enable MFA / Strong authentication and I have an issue with Conditional Access Policies about it.
For context, I deployed Windows Hello for Business on our computers with GPO, and we can use it to authenticate on Windows and also on cloud apps like Office portal.
What I want to do is to be able to login only with a Passwordless MFA solution, to disable email/password auth. So i configured the Grant control like this :
When i try the policy for a test user, it works :
But looking at the conditions of the Passwordless MFA, it shows that WHfB isn't registered for the user :
And in the User's authentication methods, there is WHfB and it is working if we use it to authenticate on Windows or any cloud app (Office Portal for example) :
Is this possible at all ? I looked at many docs from Microsoft and think the setup and configuration are correct, I have no clues left.
Thank you in advance.
Regards,