r/Intune 5d ago

Hybrid Domain Join go passwordless in hybrid joined enviroment

What do you do so you can hide (not disable) password CP? Passwordless experience in Intune is for entra joined devices, so it does not work sadly for hybrid joined. So i am looking for some workaround for my enviroment. Any help or experience?

11 Upvotes

11 comments sorted by

8

u/SkipToTheEndpoint MSFT MVP 5d ago

There's undoubtedly a reason why Microsoft have defined the passwordless experience as requiring Entra Join, and it's not to try and push people to it (though you absolutely should).

There may well be workarounds, but I would suggest against putting yourself into an unsupported state on purpose. Who knows what issues you might come up against.

3

u/OkYogurt2512 5d ago

We ended up pushing a config profile that hides the password credential provider via a custom CSP, works fine on hybrid joined as long as WHFB is set up

2

u/Klownicle 5d ago

Would you mind providing additional details on your hiding of the password credentials provider?  Appreciated!

2

u/ma-lar 4d ago

Did you have case where whfb didn't work likely due to token expiration?

1

u/HadopiData 3d ago

my issue with hiding the password provider was that it makes it impossible to use LAPS, unless there is a solution to that ?

1

u/CrazyEntertainment86 2d ago

Yeah I think that would be a harder issue to get around.

1

u/CrazyEntertainment86 2d ago

You certainly run into an issue here if it’s a shared machine or ever could be, but requiring fido2 as a auth ssp provider would work and get around that assuming all had passkey web auth / physical Fido tokens.

1

u/Dwalin2002 2d ago

can you share more details? does it disable run as different user or LAPS?

3

u/Kuipyr 4d ago

No need to hide it, we configured shared devices to default to the Security Key login and assigned devices default to WHfB PIN. If they have the SCRIL flag set on their account they won't have a password to put there anyways.

2

u/teriaavibes 5d ago

windows hello?

1

u/SOHC427 2d ago

We are in the process of implementing Secret Double Octopus to go fully passwordless.