Update hello-hybrid-cloud-kerberos-trust-provision.md

Some mistakes in this document. It needs to be corrected because it will cause confusion.
This commit is contained in:
yutoadachi
2023-05-09 19:08:24 +09:00
committed by GitHub
parent 26b336ab89
commit becce49f26

View File

@ -67,7 +67,7 @@ To configure Windows Hello for Business using an account protection policy:
1. Under **Block Windows Hello for Business**, select **Disabled** and multiple policies become available. 1. Under **Block Windows Hello for Business**, select **Disabled** and multiple policies become available.
- These policies are optional to configure, but it's recommended to configure **Enable to use a Trusted Platform Module (TPM)** to **Yes**. - These policies are optional to configure, but it's recommended to configure **Enable to use a Trusted Platform Module (TPM)** to **Yes**.
- For more information about these policies, see [MDM policy settings for Windows Hello for Business](hello-manage-in-organization.md#mdm-policy-settings-for-windows-hello-for-business). - For more information about these policies, see [MDM policy settings for Windows Hello for Business](hello-manage-in-organization.md#mdm-policy-settings-for-windows-hello-for-business).
1. Under **Enable to certificate for on-premises resources**, select **Disabled** and multiple policies become available. 1. Under **Enable to certificate for on-premises resources**, select **Not configured**
1. Select **Next**. 1. Select **Next**.
1. Optionally, add **scope tags** and select **Next**. 1. Optionally, add **scope tags** and select **Next**.
1. Assign the policy to a security group that contains as members the devices or users that you want to configure > **Next**. 1. Assign the policy to a security group that contains as members the devices or users that you want to configure > **Next**.
@ -138,7 +138,7 @@ You can configure Windows Hello for Business cloud Kerberos trust using a Group
--- ---
> [!IMPORTANT] > [!IMPORTANT]
> If the **Use certificate for on-premises authentication** policy is enabled, certificate trust will take precedence over cloud Kerberos trust. Ensure that the machines that you want to enable cloud Kerberos trust have this policy **not configured** or **disabled**. > If the **Use certificate for on-premises authentication** policy is enabled, certificate trust will take precedence over cloud Kerberos trust. Ensure that the machines that you want to enable cloud Kerberos trust have this policy **not configured**.
## Provision Windows Hello for Business ## Provision Windows Hello for Business