mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-16 02:43:43 +00:00
Merged PR 3521: Merge ms-whfb-staging to whfb-staging
- Added enrollment videos to the FAQ page for - Spelling corrections
This commit is contained in:
@ -25,7 +25,7 @@ ms.date: 09/08/2017
|
||||
>[!IMPORTANT]
|
||||
>This guide only applies to Hybrid deployments for Windows 10, version 1703 or higher.
|
||||
|
||||
In hybrid deployments, users register the public portion of their Windows Hello for Business crednetial with Azure. Azure AD Connect syncrhonizes the Windows Hello for Business public key to Active Directory.
|
||||
In hybrid deployments, users register the public portion of their Windows Hello for Business credential with Azure. Azure AD Connect synchronizes the Windows Hello for Business public key to Active Directory.
|
||||
|
||||
The key-trust model needs Windows Server 2016 domain controllers, which configures the key registration permissions automatically; however, the certificate-trust model does not and requires you to add the permissions manually.
|
||||
|
||||
|
@ -71,6 +71,23 @@ The table shows the minimum requirements for each deployment.
|
||||
|
||||
## Frequently Asked Questions
|
||||
|
||||
### What is the user experience for Windows Hello for Business?
|
||||
The user experience for Windows Hello for Business occurs after user sign once you deploy Windows Hello for Business policy settings to your environment.
|
||||
|
||||
> [!VIDEO https://www.youtube.com/embed/FJqHPTZTpNM]
|
||||
|
||||
</br>
|
||||
|
||||
> [!VIDEO https://www.youtube.com/embed/etXJsZb8Fso]
|
||||
|
||||
### What happens when my user forgets their PIN?
|
||||
|
||||
If the user can sign-in with a password, they can reset their PIN by clicking the "I forgot my PIN" link in settings. Beginning with the Fall Creators Update, users can reset their PIN above the lock screen by clicking the "I forgot my PIN" link on the PIN credential provider.
|
||||
|
||||
> [!VIDEO https://www.youtube.com/embed/KcVTq8lTlkI]
|
||||
|
||||
For on-premises deployments, devices must be well connected to their on-premises network (domain controllers and/or certificate authority) to reset their PINs. Hybrid customers can onboard their Azure tenant to use the Windows Hello for Business PIN reset service to reset their PINs without access to their corporate network.
|
||||
|
||||
### Do I need Windows Server 2016 domain controllers?
|
||||
There are many deployment options from which to choose. Some of those options require an adequate number of Windows Server 2016 domain controllers in the site where you have deployed Windows Hello for Business. There are other deployment options that use existing Windows Server 2008 R2 or later domain controllers. Choose the deployment option that best suits your environment
|
||||
|
||||
|
Reference in New Issue
Block a user