yukieryu 9a08e270c7
RDP to AADJ device using WHfB requires on-prem infrastructure and is possible with key trust deployment
(I). Suggest updating the following statement:
From : "- Cloud only, Hybrid, and On-premises only Windows Hello for Business deployments"
To: " Hybrid and On-premises Windows Hello for Business deployments"
due to the following two reasons -

(i). customer was confused that that RDP to Azure AD Joined device using WHfB was possible with "cloud only" environment (without any only-premises infrastructure). At this time, in order to RDP to Azure AD Joined device using WHfB, a certificate needs to be installed on the devices, which in turn requires on-premises infrastructure (Certificate Authority server and AD DS).

(ii) This seems to contradict with other documents detailing the procedures where it this is stated in the context of "Hybrid deployment." Other documents URL copied below -
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-base
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-cert
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-deployment-rdp-certs

(II) Suggest removing the following phrase
"This functionality is not supported for key trust deployments." because "deploying WHfB for RDP" is possible with "key trust" per following documents. 
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso-base
https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-deployment-rdp-certs
2022-08-08 09:22:08 -07:00
..
2022-07-22 11:04:08 -07:00
2022-07-22 11:04:08 -07:00
2022-08-01 17:32:58 -07:00
2022-08-01 17:32:58 -07:00
2022-08-01 17:32:58 -07:00
2022-08-01 17:32:58 -07:00