diff --git a/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust.md b/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust.md
index 584fff10d0..260e38f167 100644
--- a/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust.md
+++ b/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust.md
@@ -149,6 +149,12 @@ Once a user completes enrollment with cloud Kerberos trust, the Windows Hello ge
After enrollment, Microsoft Entra Connect synchronizes the user's key from Microsoft Entra ID to Active Directory.
+### Sequence diagrams
+
+To better understand the provisioning and authentication flows, review the following sequence diagrams:
+
+
+
## Migrate from key trust deployment model to cloud Kerberos trust
If you deployed Windows Hello for Business using the key trust model, and want to migrate to the cloud Kerberos trust model, follow these steps:
diff --git a/windows/security/identity-protection/hello-for-business/how-it-works-authentication.md b/windows/security/identity-protection/hello-for-business/how-it-works-authentication.md
index 726fbc2b1d..e50d7474e8 100644
--- a/windows/security/identity-protection/hello-for-business/how-it-works-authentication.md
+++ b/windows/security/identity-protection/hello-for-business/how-it-works-authentication.md
@@ -12,7 +12,9 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra join authentication to Microsoft Entra ID
-
+
+
+:::image type="content" source="images/howitworks/auth/entra-join-entra.svg" alt-text="Diagram of a Microsoft Entra join device authenticating to Microsoft Entra ID." lightbox="images/howitworks/auth/entra-join-entra.svg" border="false":::
> [!NOTE]
> All Microsoft Entra joined devices authenticate with Windows Hello for Business to Microsoft Entra ID the same way. The Windows Hello for Business trust type only impacts how the device authenticates to on-premises AD.
@@ -27,7 +29,9 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra join authentication to Active Directory using cloud Kerberos trust
-
+
+
+:::image type="content" source="images/howitworks/auth/entra-join-ad-ckt.svg" alt-text="Diagram of a Microsoft Entra join device authenticating to Active Directory using cloud Kerberos trust." lightbox="images/howitworks/auth/entra-join-ad-ckt.svg" border="false":::
| Phase | Description |
| :----: | :----------- |
@@ -36,7 +40,9 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra join authentication to Active Directory using a key
-
+
+
+:::image type="content" source="images/howitworks/auth/entra-join-ad-kt.svg" alt-text="Diagram of a Microsoft Entra join device authenticating to Active Directory using key trust." lightbox="images/howitworks/auth/entra-join-ad-kt.svg" border="false":::
| Phase | Description |
| :----: | :----------- |
@@ -49,7 +55,9 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra join authentication to Active Directory using a certificate
-
+
+
+:::image type="content" source="images/howitworks/auth/entra-join-ad-ct.svg" alt-text="Diagram of a Microsoft Entra join device authenticating to Active Directory using certificate trust." lightbox="images/howitworks/auth/entra-join-ad-ct.svg" border="false":::
| Phase | Description |
| :----: | :----------- |
@@ -62,7 +70,7 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra hybrid join authentication using cloud Kerberos trust
-
+:::image type="content" source="images/howitworks/auth/hybrid-entra-join-ckt.svg" alt-text="Diagram of a Microsoft Entra hybrid join device authenticating to Active Directory using cloud Kerberos trust." lightbox="images/howitworks/auth/hybrid-entra-join-ckt.svg" border="false":::
| Phase | Description |
| :----: | :----------- |
@@ -74,7 +82,9 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra hybrid join authentication using a key
-
+
+
+:::image type="content" source="images/howitworks/auth/hybrid-entra-join-kt.svg" alt-text="Diagram of a Microsoft Entra hybrid join device authenticating to Active Directory using key trust." lightbox="images/howitworks/auth/hybrid-entra-join-kt.svg" border="false":::
| Phase | Description |
| :----: | :----------- |
@@ -91,7 +101,9 @@ Microsoft Entra joined devices authenticate to Microsoft Entra ID during sign-in
## Microsoft Entra hybrid join authentication using a certificate
-
+
+
+:::image type="content" source="images/howitworks/auth/hybrid-entra-join-ct.svg" alt-text="Diagram of a Microsoft Entra hybrid join device authenticating to Active Directory using certificate trust." lightbox="images/howitworks/auth/hybrid-entra-join-ct.svg" border="false":::
| Phase | Description |
| :----: | :----------- |
diff --git a/windows/security/identity-protection/hello-for-business/how-it-works-provisioning.md b/windows/security/identity-protection/hello-for-business/how-it-works-provisioning.md
index 60f81d62ee..d5525d4164 100644
--- a/windows/security/identity-protection/hello-for-business/how-it-works-provisioning.md
+++ b/windows/security/identity-protection/hello-for-business/how-it-works-provisioning.md
@@ -19,8 +19,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Microsoft Entra joined provisioning in a managed environment
-
-[Full size image](images/howitworks/prov-aadj-managed.png)
+
+[Full size image](images/howitworks/prov/aadj-managed.png)
| Phase | Description |
|:-:|:-|
@@ -30,8 +30,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Microsoft Entra joined provisioning in a federated environment
-
-[Full size image](images/howitworks/prov-aadj-federated.png)
+
+[Full size image](images/howitworks/prov/aadj-federated.png)
| Phase | Description |
|:-:|:-|
@@ -41,8 +41,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Microsoft Entra hybrid joined provisioning in a cloud Kerberos trust deployment in a managed environment
-
-[Full size image](images/howitworks/prov-haadj-cloudtrust-managed.png)
+
+[Full size image](images/howitworks/prov/haadj-cloudtrust-managed.png)
| Phase | Description |
|:-:|:-|
@@ -55,8 +55,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Microsoft Entra hybrid joined provisioning in a key trust deployment in a managed environment
-
-[Full size image](images/howitworks/prov-haadj-keytrust-managed.png)
+
+[Full size image](images/howitworks/prov/haadj-keytrust-managed.png)
| Phase | Description |
|:-:|:-|
@@ -70,8 +70,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Microsoft Entra hybrid joined provisioning in a synchronous certificate trust deployment in a federated environment
-
-[Full size image](images/howitworks/prov-haadj-instant-certtrust-federated.png)
+
+[Full size image](images/howitworks/prov/haadj-instant-certtrust-federated.png)
| Phase | Description |
|:-|:-|
@@ -88,8 +88,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Domain joined provisioning in an On-premises Key Trust deployment
-
-[Full size image](images/howitworks/prov-onprem-keytrust.png)
+
+[Full size image](images/howitworks/prov/onprem-keytrust.png)
| Phase | Description |
| :----: | :----------- |
@@ -99,8 +99,8 @@ Windows Hello for Business provisioning enables a user to enroll a new, strong,
## Domain joined provisioning in an On-premises Certificate Trust deployment
-
-[Full size image](images/howitworks/prov-onprem-certtrust.png)
+
+[Full size image](images/howitworks/prov/onprem-certtrust.png)
| Phase | Description |
| :----: | :----------- |
diff --git a/windows/security/identity-protection/hello-for-business/how-it-works.md b/windows/security/identity-protection/hello-for-business/how-it-works.md
index bb524aeaca..ac509cca22 100644
--- a/windows/security/identity-protection/hello-for-business/how-it-works.md
+++ b/windows/security/identity-protection/hello-for-business/how-it-works.md
@@ -155,14 +155,14 @@ Windows Hello can also be used as a FIDO2 authenticator to authenticate to any w
To learn more how Windows uses the TPM in support of Windows Hello for Business, see [How Windows uses the Trusted Platform Module](../../hardware-security/tpm/how-windows-uses-the-tpm.md).
-### Windows Hello data storage
+### Biometric data storage
The biometric data used to support Windows Hello is stored on the local device only. It doesn't roam and is never sent to external devices or servers. This separation helps to stop potential attackers by providing no single collection point that an attacker could potentially compromise to steal biometric data. Even if an attacker could obtain the biometric data from a device, it couldn't be converted back into a raw biometric sample recognizable by the biometric sensor.
+Each sensor has its own biometric database file where template data is stored (path `C:\WINDOWS\System32\WinBioDatabase`). Each database file has a unique, randomly generated key that is encrypted to the system. The template data for the sensor is encrypted with the per-database key using AES with CBC chaining mode. The hash is SHA256.
+
> [!NOTE]
->Each sensor on a device has its own biometric database file where template data is stored (path `C:\WINDOWS\System32\WinBioDatabase`). Each database has a unique, randomly generated key that is encrypted to the system. The template data for the sensor is encrypted with the per-database key using AES with CBC chaining mode. The hash is SHA256.
->
->Some fingerprint sensors have the capability to complete matching on the fingerprint sensor module instead of in the OS. These sensors store biometric data on the fingerprint module instead of in the database file.
+>Some fingerprint sensors have the capability to complete matching on the fingerprint sensor module instead of in the OS. These sensors store biometric data on the fingerprint module instead of in the database file. For more information, see [Windows Hello Enhanced Security Sign-in (ESS)][WINH-1].
## Key synchronization
@@ -231,3 +231,4 @@ Changing a user account password doesn't affect sign-in or unlock, since Windows
[ENTRA-4]: /entra/identity/devices/device-registration-how-it-works
[WEB-1]: https://openid.net/specs/draft-jones-json-web-token-07.html
+[WINH-1]: /windows-hardware/design/device-experiences/windows-hello-enhanced-sign-in-security
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-cloudtrust.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-cloudtrust.svg
deleted file mode 100644
index 65d3e29787..0000000000
--- a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-cloudtrust.svg
+++ /dev/null
@@ -1,876 +0,0 @@
-
-
-
-
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-certtrust-kerb.png b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-certtrust-kerb.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-certtrust-kerb.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-certtrust-kerb.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-cloud.png b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-cloud.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-cloud.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-cloud.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-cloudtrust-kerb.png b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-cloudtrust-kerb.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-cloudtrust-kerb.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-cloudtrust-kerb.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-keytrust-kerb.png b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-keytrust-kerb.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/auth-aadj-keytrust-kerb.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-aadj-keytrust-kerb.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-certtrust.png b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-haadj-certtrust.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-certtrust.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-haadj-certtrust.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-keytrust.png b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-haadj-keytrust.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/auth-haadj-keytrust.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/auth/auth-haadj-keytrust.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-ckt.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-ckt.svg
new file mode 100644
index 0000000000..b08f1a1817
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-ckt.svg
@@ -0,0 +1,216 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-ct.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-ct.svg
new file mode 100644
index 0000000000..9d950e0cbc
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-ct.svg
@@ -0,0 +1,245 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-kt.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-kt.svg
new file mode 100644
index 0000000000..267034368c
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-ad-kt.svg
@@ -0,0 +1,245 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-entra.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-entra.svg
new file mode 100644
index 0000000000..563162bee2
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/entra-join-entra.svg
@@ -0,0 +1,367 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-ckt.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-ckt.svg
new file mode 100644
index 0000000000..af536a80b1
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-ckt.svg
@@ -0,0 +1,500 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-ct.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-ct.svg
new file mode 100644
index 0000000000..349f7cee4d
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-ct.svg
@@ -0,0 +1,541 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-kt.svg b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-kt.svg
new file mode 100644
index 0000000000..05f8168142
--- /dev/null
+++ b/windows/security/identity-protection/hello-for-business/images/howitworks/auth/hybrid-entra-join-kt.svg
@@ -0,0 +1,540 @@
+
+
+
+
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-aadj-federated.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/aadj-federated.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-aadj-federated.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/aadj-federated.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-aadj-managed.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/aadj-managed.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-aadj-managed.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/aadj-managed.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-haadj-cloudtrust-managed.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/haadj-cloudtrust-managed.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-haadj-cloudtrust-managed.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/haadj-cloudtrust-managed.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-haadj-instant-certtrust-federated.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/haadj-instant-certtrust-federated.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-haadj-instant-certtrust-federated.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/haadj-instant-certtrust-federated.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-haadj-keytrust-managed.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/haadj-keytrust-managed.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-haadj-keytrust-managed.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/haadj-keytrust-managed.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-onprem-certtrust.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/onprem-certtrust.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-onprem-certtrust.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/onprem-certtrust.png
diff --git a/windows/security/identity-protection/hello-for-business/images/howitworks/prov-onprem-keytrust.png b/windows/security/identity-protection/hello-for-business/images/howitworks/prov/onprem-keytrust.png
similarity index 100%
rename from windows/security/identity-protection/hello-for-business/images/howitworks/prov-onprem-keytrust.png
rename to windows/security/identity-protection/hello-for-business/images/howitworks/prov/onprem-keytrust.png