Windows Hello for Business - registration won't start with FIDO Key login

Kenny McMichael 0 Reputation points
2025-06-11T15:00:00.04+00:00

Have an issue where I can't get the enrollment for WHFB to work unless users log in with a password.

We are a hybrid environment - AD and Entra joined. TAP is not an option as you have to be entra only.

We have Yubikeys setup to work as an alternate login source which is linked with ENTRA ID. This works and users can sign in using these keys. The goal is passwordless with WHFB.

However when logging in using the Yubikeys - it will never prompt for registration to WHFB. I have to log out and log in with a password in order for that to happen.....

Has anyone got that to work?

Microsoft Security | Intune | Configuration
{count} votes

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.