Included with Windows Pro. Most organizations are entitled to it and have never deployed it.
The supported edition list runs from Windows Pro upward, and entitlement starts at Pro and continues through Enterprise E5. What it does is swap the password for a key bound to that specific machine, protected by its security module and unlocked with a PIN or a biometric. That PIN never travels anywhere off the device, which is the fact that answers most of the objections people raise.

- Windows ProEntitlement starts there
- Two factorsA device-bound key and a PIN or biometric
- Never leavesThe PIN, and the biometric data
- TPM protectedCredentials generated in isolated environments
Two things people conflate, and the relationship is worth stating.
Both are phishing-resistant, both get discussed in the same meeting, and they address different halves of the same problem. Being clear about which half saves a great deal of circular argument.
- One is about getting into the Windows machine in front of you, and reaching your organization resources from it, using a credential tied to that specific hardware and protected by its security module, released by a PIN or a biometric. It is fundamentally the Windows sign-in experience.
- The other is about authenticating to your organization identity across whatever devices and services somebody happens to be using, built on FIDO2 with origin-bound cryptography. Broader surface, and deliberately not bound to any single machine.
- They do overlap, and it is worth knowing that through FIDO and WebAuthn the Windows credential can also sign in to supported websites. In practice most organizations end up running both: one for the Windows fleet, the other for identity generally.
- So the sequencing question is simply which surface currently hurts more. Password resets and daily sign-in friction on Windows point one way. Phishing against your identity points the other. Check your licensing before assuming either requires a purchase, because both are usually already covered.
Eight things about Windows Hello for Business worth knowing before you deploy it.
It is included with Windows Pro
The published edition table covers Pro, Enterprise, Pro Education and Education, and the entitlement table extends from Pro right through Enterprise E5 and the Education A3 and A5 tiers. Work out which of those your fleet is running and the conclusion is almost always the same: you paid for this some years ago and nobody ever configured it.
The two factors, and why a PIN is not a weak password
The two factors are something you have, meaning a private key protected by the security module in that machine, and something you know, meaning the PIN. Somebody will always object that four digits is weaker than their password, and the objection misses three things. The PIN never leaves the device, brute force protection is built in, and without that particular laptop the PIN is worth precisely nothing to anybody.
No shared secret to steal from a server
With no symmetric secret in the picture, phishing and brute force attacks are circumvented and server breaches and replay attacks are prevented, because the credentials are asymmetric and generated inside the isolated environment of the platform module. Contrast that with a password, which by definition exists in two places at once and can therefore be stolen from either of them. The difference is structural rather than incremental.
Three biometric methods, with real thresholds behind them
Three options exist: facial recognition through infrared cameras capable of reliably telling a photograph or a scan apart from a living person, fingerprint recognition through a capacitive sensor, and iris recognition, which needs a HoloLens 2. Acceptance thresholds are published rather than asserted, including a false accept rate under 0.001 percent for facial recognition, and anti-spoofing measures are required in every sensor.
Biometric data never leaves the machine
Biometric data is held securely on the local device alone, does not roam, and is never transmitted to external devices or servers. Follow the consequence through: with nothing pooled anywhere, there is no single collection an attacker could compromise to steal it in bulk. Have that answer ready, because the privacy objection always arrives, and in states carrying biometric privacy statutes it arrives with more force.
Key trust or certificate trust
The consumer capability is key-based only. The business version supports either keys or certificates, and brings device attestation and Conditional Access policy support with it. Which trust model fits comes down to your identity infrastructure and whether you already operate a certificate authority. Of the handful of decisions in this project, this is one of the two genuinely worth getting right beforehand.
It does not work with Entra Domain Services
This is stated plainly in the documentation, and it belongs to that category of constraint which surfaces after the design is complete and everybody is pleased with it. If Entra Domain Services appears anywhere in your identity picture, establish this before you plan anything around the capability, because what awaits you is not a workaround. It is a different design entirely.
Face recognition does not work with a mask
Wearing a mask is unsupported for both enrollment and authentication, with the suggested alternative being a PIN or fingerprint wherever the working environment does not permit briefly removing one. Think about who that affects: clinical staff, laboratory technicians, food processing lines, construction sites. Handle it as a decision about which populations get which method, not as an exception somebody requests later.
Four things that decide whether this rollout is quiet.
We check entitlement first, because it is usually already there
Entitlement runs from Windows Pro through Enterprise E5 plus the Education editions, which between them cover very nearly every organization we deal with. Confirming that takes a few minutes and immediately reframes the whole discussion, since a purchase conversation and a configuration conversation involve entirely different people and timescales.
We check the blockers before designing anything
Three things constrain what is possible, and all three are cheap to check. Entra Domain Services is documented as incompatible. Machines lacking a platform module cannot participate properly. And populations with no biometric hardware get a different experience. Establishing all three in week one avoids producing a design that quietly assumes capability your estate does not possess.
We answer the biometric privacy question before anybody asks it
Within about a day of any announcement, somebody asks whether their employer now holds their fingerprint, and in states carrying biometric privacy statutes that question arrives with genuine legal weight behind it. The answer is both specific and reassuring: the data stays on the local device, does not roam, and is never transmitted to any external device or server, which means no pooled collection exists for anybody to compromise. Put that in writing before enrollment rather than after, and the objection never gains momentum. Legal interpretation belongs to your counsel; the technical facts underneath are ours.
We identify the populations that need a different answer
Masks are unsupported for both enrollment and authentication, with a PIN or fingerprint suggested wherever the working environment does not allow briefly removing one. Clinical areas, laboratories, food production lines and construction sites all contain people this affects. Planning their route in advance beats discovering the problem through a stream of failed enrollments and a service desk that cannot explain why.
Six US situations where Windows sign-in is worth changing.
A helpdesk spending its week on password resets
Of every scenario here, this is the one you can actually measure. A credential released by a PIN or fingerprint that never leaves the machine effectively eliminates the forgotten password call for whoever adopts it, and the entitlement is almost certainly sitting there already. Count your reset volume before you begin. That single number is what turns a preference into a business case somebody will fund.
A regulated firm strengthening authentication across the estate
The pattern is a second factor rigorously enforced on every cloud service while the machine itself opens on a typed password. Closing that gap brings two factors, device attestation and Conditional Access policy support to the login screen. Set that beside a password complexity rule and consider which one you would rather describe to an FTC Safeguards assessor, an NYDFS Part 500 examiner or an insurance underwriter.
An organization already deploying passkeys
Once the identity side has committed to phishing-resistant credentials, leaving the device sign-in behind makes little sense. And these two are complementary rather than competing, since the Windows credential can itself be used through FIDO and WebAuthn to sign in to supported websites. Nearly every organization that adopts one eventually runs both, so the question is sequence rather than selection.
A workforce with a genuine face covering requirement
Clinical settings, laboratories, food production and construction, where facial authentication is simply not viable given that masks are unsupported for both enrollment and authentication. Those populations go down the fingerprint or PIN route instead. Identifying who they are before you start is the difference between a smooth rollout and one that stalls in week two on enrollments nobody can explain.
An education institution on Windows Education licensing
Pro Education, Education, and the A3 and A5 entitlements all support this. Schools and universities combine two things that make the case unusually strong: very large device fleets, and populations who forget passwords at genuine scale every September. The licensing is already in place and the operational benefit scales directly with how many people you have.
An organization deploying Personal Data Encryption
This one is a dependency rather than a benefit. Personal Data Encryption on Windows 11 withholds its data encryption keys until somebody signs in with the business credential, which is precisely how it differs from BitLocker releasing keys at boot. So where file-level protection on a running machine is what you are actually after, this is not an option to weigh. It is the prerequisite.
How people actually sign in to Windows in US organizations.
| Feature | Hello for Business deployed | Users enabled Hello themselves | Passwords |
|---|---|---|---|
Credential bound to the device security module | Yes | Varies | No |
No shared secret stored on a server | Yes | Partly | No |
Resistant to phishing and replay | Yes | Partly | No |
Certificate-based option available | Yes | No | Not applicable |
Device attestation available | Yes | No | Not applicable |
Conditional Access can consume it | Yes | No | Not applicable |
Centrally managed policy | Yes | No | Partly |
Biometric data confined to the device | Yes | Yes | Not applicable |
Password reset calls | Reduced | Unchanged | Routine |
Frequency in the US mid-market | Uncommon | Common | Common |
What the enterprise extension actually adds.
Aspect
Authenticates to
- Windows Hello
- A Microsoft account, and FIDO v2.0 identity providers
- Windows Hello for Business
- A Microsoft Entra ID account, an Active Directory account, and FIDO v2.0 providers
Aspect
Credential type
- Windows Hello
- Key-based
- Windows Hello for Business
- Key-based or certificate-based
Aspect
Device attestation
- Windows Hello
- Not part of the base capability
- Windows Hello for Business
- Included in the enterprise extension
Aspect
Conditional Access policy support
- Windows Hello
- Not part of the base capability
- Windows Hello for Business
- Included in the enterprise extension
Aspect
Centrally managed policy settings
- Windows Hello
- No
- Windows Hello for Business
- Yes, deployed to devices
Aspect
With a local account
- Windows Hello
- Convenient, not backed by an asymmetric key pair
- Windows Hello for Business
- Not the intended model
Aspect
Website sign-in
- Windows Hello
- Supported through FIDO and WebAuthn
- Windows Hello for Business
- Supported through FIDO and WebAuthn
Five steps, and two of them are about people rather than devices.
- 1
Confirm entitlement, hardware, and blockers
Three questions get answered in the first week: which Windows edition the fleet runs, what platform module and biometric hardware actually exists across it, and whether Entra Domain Services appears anywhere in your identity picture, since that is documented as incompatible. Between them those answers define the outer limit of what this project can achieve.
- 2
Choose the trust model and the policy design
Keys or certificates, decided on your identity infrastructure and whether a certificate authority already exists. Then PIN requirements, whether biometrics are encouraged or mandated, and whether Conditional Access should consume the result. Take these seriously now, because every one of them becomes awkward to revisit once devices have started enrolling.
- 3
Identify the populations needing a different route
Four groups: anybody working with a face covering, machines with no biometric hardware, shared devices, and hardware that fails the requirements outright. Each gets a defined path written down beforehand rather than becoming an exception somebody discovers at the enrollment screen. In our experience these populations are consistently smaller than people fear and never once empty.
- 4
Communicate the privacy answer before enrollment starts
Somebody is going to ask whether the company now holds their fingerprint, and if the first answer they get comes from a colleague in a kitchen rather than from you, it will be wrong. The facts are that biometric data stays on the local device, does not roam, and never reaches an external device or server. Say it once, in writing, before enrollment opens.
- 5
Pilot, then roll out by population
Begin with people who have suitable hardware and who will describe a problem clearly rather than working around it. Run them through a complete cycle including a device failure and a genuine recovery before widening. Afterward, track password reset volume, since that is the figure which justified the project and the one somebody will eventually ask you about.
What organizations ask about Windows Hello for Business.
Fifteen questions worth answering first.
Entitlement and hardware
- Which Windows edition is your fleet on?Pro and above are listed as supporting it.
- Do devices have a trusted platform module?Credentials are generated in the module.
- Do they have infrared cameras or fingerprint readers?That decides which biometrics are available.
- Is Microsoft Entra Domain Services in your identity picture?Microsoft states it does not work with it.
- Are devices Entra joined, hybrid joined, or domain joined?It determines the deployment model.
Design
- Key trust or certificate trust?Both are supported and they suit different estates.
- Do you already run a certificate authority?Relevant to the trust model decision.
- Should Conditional Access consume this?Policy support is part of the business extension.
- What PIN complexity will you require?Balanced against the brute force protection already present.
- Are biometrics mandatory or optional?Users can always fall back to a PIN.
Populations needing care
- Does anybody work with a face covering?Face recognition does not support a mask.
- Are there shared devices?The credential is bound to the device and the user.
- Do any users have no biometric hardware?A PIN still works, and the experience differs.
- What is the recovery path if a device fails?Worth defining before rollout, not during.
- Has the privacy question been answered in advance?Biometric data never leaves the device.
The pages around this one.
Passwordless and passkeys
The identity side of phishing-resistant authentication, and how it complements Windows sign-in rather than replacing it.
BitLocker management
Where Personal Data Encryption sits, and why it depends on Windows Hello for Business to release its keys.
Conditional Access
The policy layer that can consume the sign-in strength this provides, rather than treating all logins alike.
Check your Windows edition, then your password reset volume.
The first tells you whether you are already entitled, which for Windows Pro and above you are. The second tells you what the deployment would save. Between them they usually make the case without anybody needing to argue for it.
Related Services
Explore more solutions that work great with this service
Phishing-Resistant MFA
Phishing-resistant multifactor authentication for US organizations:
Learn morePasswordless Authentication and Passkeys
Passwordless authentication rollouts for US organizations using
Learn moreBitLocker Disk Encryption Management with Intune
BitLocker encryption management for US businesses: pre-deployment
Learn moreMicrosoft Entra Conditional Access Design
Conditional Access design and review for US organizations:
Learn moreMicrosoft Intune
Device management and endpoint security
Learn moreMicrosoft Entra
Identity and access management solutions
Learn more