Windows Hello for Business does not work if set with Settings Catalog

Pavel yannara Mirochnitchenko 12,916 Reputation points MVP
2025-03-16T15:14:39.9966667+00:00

I tried to set WHFB with Settings Catalog, using same options as I did with Identity Protection, but it seems with SC, it works very unreliably. It only enforces WHFB on part devices, not all. Some devices receive it fast, some very late and some not at all. Assignment and status is always green, but WHFB enrollment does not kick on. I assign it to devices because we also have shared computers we don't want it to be in use.

User's image

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
491 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 17,080 Reputation points Microsoft External Staff
    2025-03-17T02:03:14.96+00:00

    @Pavel yannara Mirochnitchenko, Thanks for posting in Q&A.

    From your description, I know Windows Hello for Business does not work if set with Settings Catalog using the same options as you did with Identity Protection.

    Based on my research, Windows Hello for Business (WHFB) is designed for user-based authentication and requires each user to enroll their credentials, and WHFB enrollment is tied to a single user. So, ensure the user was assigned necessary licenses and has logon in targeted devices and sync with Intune.

    Moreover, please go to targeted devices and launch Event Viewer (eventvwr.msc) and navigate to Applications and Services Logs > Microsoft > Windows > User Device Registration > Admin to see if there exist error message.

    https://www.manishbangia.com/configure-windows-hello-for-business-using-intune/

    Non-official, just for reference.

    Please check above information, if there is any update, feel free to let me know.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Pavel yannara Mirochnitchenko 12,916 Reputation points MVP
    2025-03-17T16:01:23.98+00:00

    @ZhoumingDuan-MSFT first, if you look at Settings Catalog and Account Protection should support User and Device based deployments, option is available for both sides:

    User's image

    But the Event Viewer ID 360 says to me "Windows Hello for Business provisioning will not be launched". Same time, the policy is assigned to device successfully / green status.

    Mean while I am testing different models.


  3. Pavel yannara Mirochnitchenko 12,916 Reputation points MVP
    2025-03-20T08:25:57.5733333+00:00

    Let me share fiew events. In this case, WHFB did apply in TPM 2.0 computer but with delay. Delay does not matter, but I wanted to compare events. So, this are events from WHFB computer:

    User's image

    and later it is fine:

    User's image

    0 comments No comments

  4. Pavel yannara Mirochnitchenko 12,916 Reputation points MVP
    2025-03-20T08:27:56.3733333+00:00

    Now let me share events from computer with WHFB never applying.
    User's image

    and

    User's image


  5. Pavel yannara Mirochnitchenko 12,916 Reputation points MVP
    2025-03-20T18:15:59.66+00:00

    Hmm.... in one TPM 1.2 computer, WHFB started working after ms update patching. I reviewed the logs and saw, that this value changes to 0x00000000 after patching restart and then WHFB hits on. But this situation takes few days after autopilot.

    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.