<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009zu4aMCAQOkta Classic EngineMulti-Factor AuthenticationAnswered2026-03-22T09:00:29.000Z2024-02-12T17:13:28.000Z2024-02-14T09:32:22.000Z

qxp1l (qxp1l) asked a question.

Windows Hello for Business initial setup w/ Microsoft Intune

Once we have deployed our Windows devices via Intune, users are prompted to setup Windows Hello for Business as we encourage the user of Fingerprint / Face ID for device login. I understand this is classed as a form of MFA by Microsoft and therefore requires another form other than a password. This is understandable and with a Sign in Policy in Okta requiring 2 factors, this can be allowed (Okta MFA to Azure MFA is enabled).

However, the issue with this is we would like to setup a Device Trust based policy structure that only allow Modern Authentication on devices that are registered and managed by Intune (Single factor authentication allowed on managed devices, otherwise, denied). This becomes problematic as the Windows Hello for Business prompt is classed as Modern Auth, therefore triggers a policy which would need 2 factors - this in turn appears to prompt for Okta Verify during the setup of WHfB and cannot be completed as the Okta Verify screen doesn't display over the top of the WHfB screen.

 

I do not want it so Modern Authentication on our Managed devices requires 2 factors and I do not want users to be able to setup Outlook, Word etc on non Managed devices. Is this possible with a custom expression or possibly with another feature outside the managed devices?

 

Thanks.


This question is closed.
Loading
Windows Hello for Business initial setup w/ Microsoft Intune