Skip to content

Set up Windows Hello

Now you set up Windows Hello for Microsoft Entra ID (Azure AD) users.

You can do this for all users in your Azure tenant, or for specific Microsoft Entra ID (Azure AD) user groups.

Click All users or Specific groups to see how.

  1. Go to the Microsoft Azure portal.

  2. Go to Devices > Device settings. Turn on Users may join devices to Microsoft Entra ID (Azure AD).

    Device settings page.

  3. Go to https://endpoint.microsoft.com to open the Microsoft Endpoint Manager admin center.

    Alternatively, in the Azure Portal, you can go to Devices > Overview > Feature Highlights, click Intune, and follow the link to Microsoft Endpoint Manager.

  4. In Microsoft Endpoint Manager, select Devices.

    Microsoft Endpoint Manager.

  5. Select Windows Enrollment and click Windows Hello for Business.

    Windows Enrollment page.

  6. In Configure Windows Hello for Business, select Enabled.

    Configure the authentication method you want to use.

    Hello for Business settings.

  1. Go to the Microsoft Azure portal.
  2. Go to Devices > Device settings. Turn on Users may join devices to Microsoft Entra ID (Azure AD).

    Device settings page.

  3. Go to https://endpoint.microsoft.com to open the Microsoft Endpoint Manager admin center.

    Alternatively, in the Azure Portal, you can go to Devices > Overview > Feature Highlights, click Intune, and follow the link to Microsoft Endpoint Manager.

  4. In Microsoft Endpoint Manager, select Devices.

    Microsoft Endpoint Manager.

  5. Go to Configuration profiles > Create profile.

  6. Enter the properties as follows:

    1. In Platform, select Windows 10 and later.
    2. In Profile, click Templates > Identity protection.
    3. Click Create.

  7. In Basics, enter a Name and Description. Click Next.

  8. In Configuration settings, do as follows:

    1. In Configure Windows Hello for Business, select Enabled.
    2. Configure the authentication method you want to use. For details of all settings, see Identity protection profile settings.
    3. Click Next.

    Configuration settings.

  9. In Assignments, add user groups to the Included groups. These groups will use Windows Hello. Click Next.

    Assignments.

  10. In Review + create, review your settings and click Create.

Next you join computers to Azure.