4iT IT Support Sydney | Your Reliable Sydney IT Support Partner

Insights & News

Windows Hello for Business: Passwordless Sign-In for SMEs

Windows Hello for Business replaces the password at Windows sign-in with a key pair held in the device's security chip, unlocked by a fingerprint, face or PIN. It is phishing-resistant, it is included in the Windows and Microsoft 365 licences you already hold, and it runs on hardware most businesses already own. With Microsoft retiring its own SMS and voice authentication in February 2027, it is one of the two obvious places for an Australian SME to land, and for staff on company laptops it is the one that removes friction rather than adding it.

Person signing in to a Windows laptop using facial recognition in an office.

Key facts

  • The credential is a key pair bound to that specific device and protected by its TPM security chip. The private key never leaves the device and is never sent to any server.
  • The PIN is not a password. It only unlocks the local key on that one device, so it is useless to anyone who does not have the device in hand.
  • It is phishing-resistant. There is no password or code for a fake login page to capture, and the credential cannot be used from another machine.
  • No extra licence is required. Windows Hello for Business is part of Windows and is configured through Intune or Group Policy.
  • A cloud-only deployment, where devices are joined to Microsoft Entra ID with no on-premises Active Directory, needs no PKI at all.
  • For hybrid environments that still have on-premises Active Directory, Microsoft recommends cloud Kerberos trust, which also avoids deploying a PKI.
  • Requirements for cloud Kerberos trust: Windows 10 21H2 or Windows 11, domain controllers on Server 2016 or later, and Entra Connect 2.1.16.0 or later.

Why is a PIN more secure than a password?

This is the objection every rollout meets, usually from the person who has to approve it, and the answer is worth having ready. A password is a shared secret: it is verified by a server, it travels to that server, and it works from any device anywhere. Anyone who obtains it can use it from the other side of the world.

A Windows Hello PIN is not a shared secret. It never leaves the machine and it is not checked by any server. All it does is unlock a private key that lives in that device's TPM, and it is that key which proves who you are. The PIN is worthless without the physical device, and the TPM rate-limits and eventually locks out repeated guessing, so a short PIN cannot be brute-forced the way a short password can. Someone who watches a staff member type their PIN gains nothing unless they also steal the laptop.

Which deployment model does an SME need?

If your devices are joined directly to Microsoft Entra ID and you have no on-premises server, you are in the simplest case. Cloud-only deployment needs no certificates and no PKI. It is a policy in Intune, a hardware check, and a communications plan for staff. Most businesses in this position could have it running in a week.

If you still have an on-premises Active Directory, and plenty of Australian SMEs do because of a file server or a line of business application, use cloud Kerberos trust. Microsoft recommends it over the older key trust and certificate trust models specifically because it removes the PKI requirement, which is where these projects historically bogged down. Entra ID issues a partial Kerberos ticket that your domain controllers accept, so staff still reach on-premises file shares and intranet applications without a password. It uses the same underlying Entra Kerberos setup as FIDO2 security key sign-in, so if you have already done that, much of the groundwork exists.

The models to avoid for a new deployment are key trust and certificate trust. Both require certificates and both are more work to run. They still exist for environments with a specific certificate authentication requirement, and if you inherited one it is worth planning a migration rather than extending it.

What needs checking before you start?

Hardware first. Windows Hello for Business wants a TPM, and while it can operate without one, you would not deploy it that way because the security argument depends on the chip. Any business laptop bought in the last several years has TPM 2.0. Biometrics are a separate question: a fingerprint reader or an infrared camera makes the experience better, but a PIN alone is a complete and secure implementation, so older machines without a camera are not blocked.

Then the rollout mechanics. Target a security group rather than the whole tenant so you can pilot with a handful of willing people, find the surprises, and expand. The surprises are usually a shared machine that several staff sign into, a device with an out-of-date TPM firmware, or an application that prompts for a password separately and therefore does not benefit. None of those are blockers, they just need to be known before the rest of the business is affected.

Then the communication. Passwordless sign-in is a visible change to how people start their day, and the reaction is far better when someone has explained it beforehand. This sits alongside the wider identity work: see multi-factor authentication, passkeys versus passwords and the SMS and voice MFA retirement.

Frequently asked questions

Is Windows Hello for Business the same as the PIN on a home laptop?

They look identical to the user and work differently underneath. Consumer Windows Hello secures a local or personal Microsoft account on one machine. Windows Hello for Business is centrally managed through Intune or Group Policy, tied to your work identity in Microsoft Entra ID, backed by policy you control, and reportable. That management layer is what makes it an organisational control rather than a convenience feature, and it is why the business version can be required, audited and recovered.

Do we need a certificate authority to deploy it?

Not in the two models an SME should be using. A cloud-only deployment, with devices joined to Microsoft Entra ID and no on-premises Active Directory, requires no PKI. For hybrid environments, cloud Kerberos trust also requires no PKI, which is the main reason Microsoft recommends it over key trust and certificate trust. The older models do need certificates, and that historically made Windows Hello for Business look harder than it is.

Will it still work with our on-premises file server?

Yes, with cloud Kerberos trust. Microsoft Entra ID issues a partial Kerberos ticket-granting ticket that your on-premises domain controllers convert and accept, so staff reach file shares and internal applications without entering a password. The requirements are domain controllers on Windows Server 2016 or later, Entra Connect 2.1.16.0 or later, and Windows 10 21H2 or Windows 11 on the clients. Devices do need network access to a domain controller for on-premises single sign-on to work.

What about staff whose laptops have no fingerprint reader or camera?

They use a PIN, and that is a complete implementation rather than a downgrade. The PIN unlocks a key held in the device's TPM, so it is device-bound and phishing-resistant in exactly the same way as the biometric option. Biometrics are a convenience layer on top of the same credential. It is worth specifying infrared cameras or fingerprint readers on the next hardware refresh because staff prefer them, but there is no need to wait for new machines to start.

If you are working out where to move staff as SMS authentication disappears, Windows Hello for Business is the option that makes signing in faster rather than slower. We can check your hardware and identity setup, pick the right deployment model, pilot it and roll it out. Request a callback and we will scope it.

Brett Muscio

About the author

Brett Muscio is the Director of 4iT Support Pty Ltd, a managed services provider based in Castle Hill, NSW. He works with SME clients across Sydney, Melbourne, and Brisbane on cybersecurity, including passwordless sign-in and Windows Hello for Business, Microsoft 365 hardening, multi-factor authentication, and identity and access management, with on-site support across the Sydney metro area and remote delivery nationally. Connect on LinkedIn.

Recent Posts

Scroll to Top

Thanks!

We've received your request.

We'll call you back the same business day

Book a meeting

Tell us a bit about your business

We'll call you back the same business day

What are you interested in?
What are you trying to solve?

Contact details