Merge pull request #4454 from lindspea/patch-27

Update hello-hybrid-cert-trust-prereqs.md
This commit is contained in:
Daniel Simpson
2019-07-22 15:00:25 -07:00
committed by GitHub

View File

@ -112,6 +112,9 @@ Organizations wanting to deploy hybrid certificate trust need their domain joine
Hybrid certificate trust deployments need the device write back feature. Authentication to the Windows Server 2016 Active Directory Federation Services needs both the user and the computer to authenticate. Typically the users are synchronized, but not devices. This prevents AD FS from authenticating the computer and results in Windows Hello for Business certificate enrollment failures. For this reason, Windows Hello for Business deployments need device writeback, which is an Azure Active Directory premium feature. Hybrid certificate trust deployments need the device write back feature. Authentication to the Windows Server 2016 Active Directory Federation Services needs both the user and the computer to authenticate. Typically the users are synchronized, but not devices. This prevents AD FS from authenticating the computer and results in Windows Hello for Business certificate enrollment failures. For this reason, Windows Hello for Business deployments need device writeback, which is an Azure Active Directory premium feature.
> [!NOTE]
> Windows Hello for Business is tied between a user and a device. Both the user and device need to be synchronized between Azure Active Directory and Active Directory, and therefore the device writeback is used to update the msDS-KeyCredentialLink on the computer object.
### Section Checklist ### ### Section Checklist ###
> [!div class="checklist"] > [!div class="checklist"]
> * Azure Active Directory Device writeback > * Azure Active Directory Device writeback