Latest / The Windows Podcast with Fexingo: Microsoft, PC, and Enterprise Windows Conversations / Windows 11 Quietly Mandates Enterprise Windows Hello for Business
Transcript
- Lucas: If you've been following enterprise Windows deployments over the past couple of years, you've probably noticed Microsoft quietly turning the screws on passwords. And with Windows 11, they're taking the next big step — making Windows Hello for Business effectively mandatory for enterprise logins. Luna: I've seen the announcements, but 'effectively mandatory' — what does that actually mean for IT admins? Is there a hard deadline? Lucas: Great question. There's no single kill-date for passwords across all of Windows 11 Enterprise. But the path is clear. Starting with Windows 11 version 24H2, which shipped last fall, Microsoft introduced a policy called 'EnablePasswordlessExperience' — and it's on by default for enterprise SKUs. That policy pushes users toward Windows Hello for Business during setup and silently disables password-based sign-in after a grace period. Luna: So it's not a hard block immediately, but a nudge that becomes a requirement over time? Kind of like how they handled the deprecation of NTLM? Lucas: Exactly right. They're using the same playbook. First, they make the new method easy to adopt. Then they start warning that the old method is deprecated. Eventually, they remove it. For Windows Hello, the deprecation of password sign-in for Azure ad joined devices was announced in the 2025 Windows IT Pro blog — they said password authentication would be fully removed in a future feature update, likely targeting 2027 or 2028. Luna: That's a pretty aggressive timeline when you consider how many enterprises still rely on password-based RDP or local admin accounts. Lucas: It is. And that's exactly the tension. Microsoft's argument is straightforward: passwords are the root cause of the vast majority of breaches. The 2024 Microsoft Digital Defense Report found that 99.9 percent of account compromise attacks involve password-based credentials. So from a security standpoint, eliminating passwords is a huge win. But from an IT operations standpoint, it's a massive transition. Luna: And Windows Hello for Business isn't just a fingerprint sensor on a laptop. It requires infrastructure — certificate services or cloud trust, plus TPM 2.0, which we talked about back in episode 58. Lucas: Right. Windows Hello for Business can work in three modes: key trust, certificate trust, and cloud trust. Each has its own deployment complexity. For shops still on-premises with Active Directory, certificate trust is the most common path, and that means standing up or extending a PKI. That's not trivial. Luna: How about hardware? We've seen enterprises with older Dell Latitude or HP EliteBooks that lack biometric readers. Can they use a PIN instead? Lucas: Absolutely. Windows Hello for Business includes PIN as a gesture. In fact, the PIN is actually a stronger credential than a password, because it's tied to the specific device via the TPM. So even if someone steals the PIN, they can't use it from another machine. That's the beauty of key-based authentication. But you do need TPM 2.0 — which has been mandatory on Windows 11 from the start, so any certified device should have it. Luna: That's lucky timing. The TPM mandate that caused so much friction during the Windows 11 rollout is now paying off for this passwordless push. Lucas: It really is. Microsoft designed Windows 11 from the ground up with hardware root of trust in mind, and Hello for Business is one of the key features that relies on it. Without that TPM requirement, this transition would be much harder. As it is, the main barrier is organizational — changing user behavior and updating processes. Luna: Speaking of user behavior — how do you handle shared workstations, like shift workers in a factory or a hospital? Windows Hello has historically been tied to a single user per device. Lucas: That's a real pain point, and Microsoft has been slow to address it. Windows Hello for Business does support 'shared PC mode' now, but it's still not as seamless as a simple username-password combo for rapid handoffs. In those scenarios, some organizations are using Windows Hello with a PIN for each user, and the fast-switch user feature works reasonably well. But it's not perfect. Luna: So what should an IT admin do today to prepare for this mandatory shift? Lucas: First, audit your current device fleet for TPM 2.0 and biometric readiness. Second, pilot Windows Hello for Business in a non-production environment — start with cloud trust if you're in Azure AD, or certificate trust if you're on-prem. Third, educate users early. The transition is coming, and it's better to be proactive than to have users locked out when the policy flips. Microsoft has made it clear: the password era in Windows Enterprise is ending. Luna: And on that note, I think a lot of our listeners are in the thick of these migrations. If today's conversation gave you something actionable, that's exactly why we do this show. We keep it ad-free and listener-supported — a handful of people chip in monthly at buy me a coffee dot com slash fexingo, and that literally funds episodes like this. Lucas: Yeah, and it's a small group that makes it possible for us to go deep on these niche IT topics. So if you find value in the show, that's the way to keep it going. No pressure, just a sincere thanks to those who already do. Luna: Alright, back to the technical side. Another dimension of this mandate is that Windows Hello for Business is also becoming the gateway for other authentication flows — like signing into VPNs, Wi-Fi, and even applications via WebAuthn. Lucas: That's a key point. Once you have Windows Hello set up, it can serve as the device's root of trust for FIDO2 security keys, which means you can use biometrics or PIN to authenticate to any service that supports the FIDO2 standard. And Microsoft has been pushing FIDO2 support in their own products — Azure AD, Office 365, and even Windows sign-in itself. Luna: So this isn't just about logging into Windows. It's about creating a single, strong credential that works across the entire ecosystem. That's the passwordless vision Microsoft has been talking about since 2018. Lucas: Exactly. And with Windows 11, they're finally enforcing it. The 'EnablePasswordlessExperience' policy is just the first step. In the upcoming Windows 11 25H2 release, which is expected later this year, there are rumors that password authentication for Azure ad joined devices will be completely blocked unless you explicitly enable it via Group Policy. That's a big shift. Luna: What about hybrid-joined devices? Those still on-prem AD but connected to Azure AD? Lucas: That's the tricky part. For hybrid-joined devices, Windows Hello for Business can work with certificate trust, but the policy enforcement is less aggressive. Microsoft seems to be targeting pure cloud-first scenarios first, then gradually tightening the screws on hybrid. But the direction is the same: passwords are going away. Luna: We did an episode on cloud-only identity back in episode 67. This feels like the logical conclusion of that trend. Lucas: It is. And credential guard, which we covered in episode 69, is another piece of the puzzle. Together, these features create a hardware-backed, passwordless, zero-trust authentication chain. That's the direction Microsoft wants every enterprise to go. Luna: For listeners who want to get started, what's the single most important policy to enable today? Lucas: I'd say the 'Windows Hello for Business' policy itself — it's under Computer Configuration > Administrative Templates > Windows Components > Windows Hello for Business. Set it to 'Enabled' and choose your key provider. If you're in Azure AD, select 'Use cloud trust.' That alone will start the migration. Then set the 'EnablePasswordlessExperience' policy to 'Enabled' to nudge users. Monitor adoption over a few months, then consider blocking passwords entirely via the 'DisablePasswordAuthentication' policy. Luna: And be ready for help desk calls. Users love their passwords, even though they're insecure. Lucas: Absolutely. Change management is often the hardest part. But once users experience the convenience of a fingerprint or a PIN, most never want to go back. It's faster, more secure, and once you're set up, you don't have to remember a complex password. Luna: Alright, so to summarize: Windows Hello for Business is becoming mandatory. Start planning now. Audit your hardware, pick your trust model, and communicate with users. The password is on its way out. Lucas: And for those of you who want to dig deeper, Microsoft's documentation on Windows Hello for Business deployment is actually quite good. There's a step-by-step guide on their website. I'll link to it in the show notes — well, you know, the show notes that exist in the podcast app. Luna: Thanks for listening, and if you found this useful, consider supporting the show at buy me a coffee dot com slash fexingo. It's what keeps these deep dives coming. Lucas: Next time, we'll look at another quiet mandate: how Windows 11 is pushing enterprises toward Microsoft Defender for Endpoint as the default antivirus. Until then, stay secure.