Sign-in for Windows that needs no password and resists phishing, provided the device has suitable hardware.
Also called WHfB.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500SC-900AB-900SC-300MD-102
Each book explains Windows Hello for Business in context, with comparison tables and the common traps.
Related terms
- Account protection
Covers Windows LAPS, local user group membership, Credential Guard and Windows Hello for Business in a single Intune endpoint security policy type for Windows. Since July 2024 it has replaced the Identity protection template.
- Certificate trust
With this Windows Hello for Business model, AD FS acts as registration authority while an enterprise PKI hands users their sign-in certificates. Its hybrid form depends on AD FS federation, and cloud Kerberos trust is now Microsoft's preferred choice.
- Cloud Kerberos trust
Microsoft's preferred model for hybrid Windows Hello for Business. Microsoft Entra Kerberos hands out a partial ticket-granting ticket, a domain controller swaps it for a complete one, and there is no need for PKI or synchronising keys.
- Key trust
A Windows Hello for Business deployment model where a key bound to the device signs users in to Active Directory through certificate-based Kerberos, which means domain controllers must hold certificates. Microsoft now prefers cloud Kerberos trust.
- Passwordless authentication
Replaces the password with a device you own plus a PIN or biometric; examples include passkeys, Microsoft Authenticator and Windows Hello for Business.
- Phishing-resistant MFA
Authentication that is tied to the real website and the user's device, so a fake site cannot capture and replay it. Examples include passkeys (FIDO2), Windows Hello for Business and certificate-based authentication used as multifactor; Conditional Access can demand these through a built-in authentication strength.
- PIN
A brief secret code. The Windows Hello for Business kind is bound to a single machine and protected by its TPM, which means it stays put rather than travelling like a password does. App protection policies may additionally ask for a separate app-level code.
- Register security information
Lets a Conditional Access policy kick in at the moment someone enrols methods for MFA or SSPR, for instance demanding a Temporary Access Pass or a trusted location. Enrolment of Windows Hello for Business and macOS Platform SSO has been covered too since July 2026.