diff --git a/windows/security/identity-protection/hello-for-business/deploy/includes/tooltip-trust-cloud-kerberos.md b/windows/security/identity-protection/hello-for-business/deploy/includes/tooltip-trust-cloud-kerberos.md index cb9d49f23b..57fd74f5c3 100644 --- a/windows/security/identity-protection/hello-for-business/deploy/includes/tooltip-trust-cloud-kerberos.md +++ b/windows/security/identity-protection/hello-for-business/deploy/includes/tooltip-trust-cloud-kerberos.md @@ -3,4 +3,4 @@ ms.date: 12/08/2022 ms.topic: include --- -[cloud Kerberos trust :::image type="icon" source="../images/information.svg" border="false":::](../../hello-how-it-works-technology.md#cloud-kerberos-trust "This trust type uses security keys to authenticate the users to Active Directory. It's not required to issue any certificates, making it the recommended choice for environments that do not need certificate authentication") \ No newline at end of file +[cloud Kerberos trust :::image type="icon" source="../images/information.svg" border="false":::](../../hello-how-it-works-technology.md#cloud-kerberos-trust "This trust type uses security keys to authenticate the users to Active Directory. It's not required to issue any certificates, making it the recommended choice for environments that don't need certificate authentication") \ No newline at end of file diff --git a/windows/security/identity-protection/hello-for-business/deploy/on-premises-key-trust.md b/windows/security/identity-protection/hello-for-business/deploy/on-premises-key-trust.md index 5b0dbd90fa..961219b27e 100644 --- a/windows/security/identity-protection/hello-for-business/deploy/on-premises-key-trust.md +++ b/windows/security/identity-protection/hello-for-business/deploy/on-premises-key-trust.md @@ -13,12 +13,12 @@ Windows Hello for Business replaces username and password authentication to Wind 1. [Validate and configure a PKI](on-premises-key-trust-pki.md) 1. [Prepare and deploy AD FS](on-premises-key-trust-adfs.md) -1. [Validate and deploy multi-factor authentication (MFA)](on-premises-key-trust-mfa.md) +1. [Validate and deploy multifactor authentication (MFA)](on-premises-key-trust-mfa.md) 1. [Configure Windows Hello for Business Policy settings](on-premises-key-trust-enroll.md) ## Create the Windows Hello for Business Users security group -While this is not a required step, it is recommended to create a security group to simplify the deployment. +While this isn't a required step, it's recommended to create a security group to simplify the deployment. The *Windows Hello for Business Users* group is used to make it easy to deploy Windows Hello for Business in phases. You assign Group Policy permissions to this group to simplify the deployment by adding the users to the group. This provides users with the proper permissions to provision Windows Hello for Business.