Should Windows Hello for Business Be Managed with GPO or Intune on Hybrid-Joined Devices?

0
5
Asked By MapleOrbit47 On

I'm implementing Windows Hello for Business in an environment with on-premises Active Directory, domain controllers, and SCCM. After correcting my wording, all of our Windows devices are hybrid-joined rather than Entra-only joined, and they currently aren't managed or co-managed through Intune. We expect to keep our existing AD and SCCM setup for the foreseeable future. Since we already use Group Policy for most device settings, would you continue deploying WHfB through GPO, or would it be better to move toward Intune configuration policies and the Settings Catalog? Most remote devices automatically connect through Always On VPN to retrieve Group Policy, so I'm also interested in whether that changes the recommendation.

3 Answers

Answered By LumenTrail62 On

I’d still work toward co-management and an Intune-centered approach when you can. Intune makes it easier to support remote devices, apply configuration without depending on domain connectivity, and gradually move away from on-premises dependencies. You don’t have to migrate everything at once—WHfB can be an early workload while SCCM and GPO continue handling the rest.

RiverQuartz5 -

The recommendation still applies even with Always On VPN. VPN solves connectivity and policy retrieval, while Intune provides cloud-based enrollment, reporting, and configuration that can be useful when devices aren’t consistently connected to the corporate network.

Answered By QuietHarbor8 On

Because these devices are hybrid-joined, GPO is a perfectly valid way to deploy Windows Hello for Business, including Cloud Kerberos Trust and the related enrollment settings. If your existing management model is centered on AD and SCCM, using GPO will likely be the least disruptive option. You may need separate policies or a staged process so the device registration happens first and the WHfB settings apply after the user has signed in.

CedarVibe29 -

Always On VPN helps remote devices reach domain resources and refresh policy, but it doesn’t remove the management advantages of Intune. It mainly makes your current GPO approach more practical for off-network users.

Answered By SilverKite31 On

A practical setup is to use one GPO to enable device registration and another to configure the WHfB enrollment experience, including Cloud Kerberos Trust. Be aware that enrollment may not be completely seamless: in some environments, the user must sign in once before the device can be targeted by the rest of the WHfB policy. A pilot group and staged rollout can help identify those timing issues before broad deployment.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.