Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate.

MITAuto-check passedBackend & APIs

Install Windows Hello

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills windows-hello --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/windows-hello .claude/skills/windows-hello && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
windows-hello
GitHub stars
175
Token cost
~2k tokens
SKILL.md length
859 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate.

  • Works in 7 steps: Verify prerequisites — Devices: Windows… → Provision via Intune — Use Intune… → PIN complexity and biometric policy —… → …
  • FIDO2 security keys (use entra-id)
  • SKILL.md covers When to use, Pick the trust model, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Windows Hello is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. Covers trust model selection (cloud Kerberos trust default for hybrid; key trust legacy; certificate trust niche), prerequisites (Entra join, MFA registration, Entra Kerberos for cloud Kerberos trust), Intune-based provisioning, multi-factor unlock, and Conditional Access authentication strengths. WHEN: Windows Hello for Business, WHfB, passwordless…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authentication. It works with Microsoft Entra ID. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • FIDO2 security keys (use entra-id)
  • CA policy authoring (use conditional-access-mfa)
  • Intune compliance baseline (use intune-device-mgmt)

Example prompts

  • “/windows-hello”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Verify prerequisites — Devices: Windows 10 1903+ / Windows 11; TPM 2.0 (TPM 1.2 in
  2. Provision via Intune — Use Intune Account Protection policy (preferred) or the
  3. PIN complexity and biometric policy — Minimum 6 digits (6-8 typical); allow biometric
  4. Disable convenience PIN — Some legacy estates have "convenience PIN" enabled (a PIN
  5. Conditional Access - authentication strength — Create a CA policy that requires
  6. Multi-factor unlock for shared / kiosk — On devices accessed by multiple users (lab,
  7. Plan credential recovery (PIN reset) and shared-device scenarios — Configure

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Windows Hello loads about 2k tokens when it runs. Until then it costs about 218 tokens; SKILL.md has 859 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~218
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 859 words, ~2,028 tokens.

Download SKILL.mdSave it as .claude/skills/windows-hello/SKILL.md (or your agent's skills folder).
name
windows-hello
description
Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. Covers trust model selection (cloud Kerberos trust default for hybrid; key trust legacy; certificate trust niche), prerequisites (Entra join, MFA registration, Entra Kerberos for cloud Kerberos trust), Intune-based provisioning, multi-factor unlock, and Conditional Access authentication strengths. WHEN: Windows Hello for Business, WHfB, passwordless Windows, biometric sign-in, PIN sign-in, cloud Kerberos trust, key trust, certificate trust, hybrid sign-in, Entra Kerberos, multi-factor unlock, FIDO2 vs Hello, Hello provisioning. DO NOT USE for FIDO2 security keys (use entra-id), CA policy authoring (use conditional-access-mfa), or Intune compliance baseline (use intune-device-mgmt).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Windows Hello for Business

Windows Hello for Business (WHfB) replaces passwords on Windows with a phishing-resistant 2-factor credential: a PIN or biometric (something you know/are) that unlocks a per-device asymmetric key (something you have, bound to TPM). The credential never leaves the device and is not replayable.

When to use

Eliminating password sign-in on Windows endpoints and meeting phishing-resistant MFA requirements for users on Windows. Use this skill to choose the trust model, satisfy prerequisites, and roll out provisioning.

Do not use this skill for FIDO2 keys on shared devices (entra-id), CA policy (conditional-access-mfa), or device compliance (intune-device-mgmt).

Pick the trust model

WHfB has three trust models. The choice depends on whether on-prem AD SSO is needed and the state of the AD environment.

ScenarioTrust modelWhy
Cloud-only (Entra-joined, no on-prem AD)Cloud-only (default)No on-prem trust needed
Hybrid (Entra-joined / hybrid-joined, AD SSO needed)Cloud Kerberos trust (recommended)Simplest hybrid model; requires Entra Kerberos server objects
Hybrid, can't deploy Entra KerberosKey trustLegacy; needs Windows Server 2016+ DCs + cert on each DC
Hybrid with strict cert-based environmentCertificate trustRequires AD CS + NDES + Intune cert connector; most complex

Rule of thumb: cloud Kerberos trust is the default for hybrid in 2026 unless there is a specific blocker (no Entra Connect Sync, regulated environment forbidding new auth models). Don't deploy key trust or certificate trust on new tenants - both are legacy.

Approach

  1. Verify prerequisites — Devices: Windows 10 1903+ / Windows 11; TPM 2.0 (TPM 1.2 in limited cases). Users: Entra-joined or hybrid-joined; MFA registered; supported license. For cloud Kerberos trust: deploy Entra Kerberos server objects in AD (Set-AzureADKerberosServer). Verify: dsregcmd /status shows AzureAdJoined = YES; Get-AzureADKerberosServer returns one object per AD forest.

  2. Provision via Intune — Use Intune Account Protection policy (preferred) or the legacy WHfB Identity Protection profile. Set tenant-wide WHfB off, then target-on via Intune profile for the pilot ring; don't enable tenant-wide WHfB on day one. Verify: pilot device shows the WHfB provisioning experience at first sign-in; PIN complexity matches policy.

  3. PIN complexity and biometric policy — Minimum 6 digits (6-8 typical); allow biometric (Windows Hello face / fingerprint) on supported hardware. Don't require special characters in PIN - it's not a password, it's a local unlock.

  4. Disable convenience PIN — Some legacy estates have "convenience PIN" enabled (a PIN for password fill, not WHfB). Disable it explicitly; otherwise users may end up with the wrong credential type and think they're using WHfB.

  5. Conditional Access - authentication strength — Create a CA policy that requires phishing-resistant MFA authentication strength for sensitive apps. WHfB satisfies it; password+SMS does not. Combine with PIM and PAW for Tier 0. Verify: CA What If on a sensitive app with a password-only sign-in = blocked.

  6. Multi-factor unlock for shared / kiosk — On devices accessed by multiple users (lab, shared kiosk), configure multi-factor unlock (PIN + biometric, or PIN + trusted signal).

  7. Plan credential recovery (PIN reset) and shared-device scenarios — Configure Microsoft PIN reset service so users self-recover without help desk; alternative is destructive reset (re-provision WHfB credential from scratch). Plan and communicate before rollout. Verify: PIN reset tested end-to-end by pilot user.

Show full SKILL.md (344 more words)Show less

Guardrails

  • PIN is not a password. It's local-only, device-bound, backed by TPM. Don't enforce password-style complexity (rotation, special chars) - it discourages adoption without improving security.
  • TPM-bound is the security property. A device without TPM (or with TPM disabled in BIOS) gets software fallback - much weaker. Verify TPM presence before counting WHfB as phishing- resistant.
  • WHfB credentials are per device, per user. A user with 3 devices has 3 WHfB credentials. Lost device = revoke that credential, others unaffected.
  • Don't deploy certificate trust on new tenants. Operational complexity vastly exceeds cloud Kerberos trust. Pick certificate trust only with explicit justification.
  • CA authentication strength is the lever. Without "require phishing-resistant MFA" CA policy, users can still use password+SMS for sensitive apps; WHfB rollout alone doesn't block weak auth.
  • Plan PIN reset before rollout. Forgotten PINs on day 2 of rollout, no recovery, = ticket storm and rollback.

Common anti-patterns

  • "Enable WHfB tenant-wide and roll forward" - Forced enablement breaks shared devices, non-TPM devices, and edge cases. Intune-target rings.
  • "Require 14-character complex PIN" - Users hate it, write it down, adopt slower. 6 digits is the recommendation.
  • "Deploy key trust for the new tenant" - Legacy. Cloud Kerberos trust unless blocked.
  • "WHfB rollout - we're done with MFA" - WHfB is great for Windows sign-in; CA policy still required to extend the phishing-resistant property to apps.
  • "Disable TPM to make troubleshooting easier" - Strips the security property; WHfB becomes software-only. Re-enable.
  • "Convenience PIN is the same as WHfB" - Different credential type, weaker. Disable convenience PIN explicitly.

Example prompts

  • Choose between cloud Kerberos trust and key trust for our hybrid deployment.
  • Roll out Windows Hello for Business via Intune to a 50-device pilot ring.
  • Configure phishing-resistant MFA authentication strength in Conditional Access for SharePoint admin.
  • Set up the PIN reset service so users can self-recover.
  • Why do my hybrid users still get prompted for password after WHfB enrollment?
  • Plan multi-factor unlock on shared lab devices.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/windows-hello of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Windows Hello next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Windows Hello compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Windows Hello this skillvinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
Msal Client CredentialsAzureAD/microsoft-authentication-library-for-dotnet1.5k—~1.1kAutomated safety check: PassMIT
Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills202—~1.5kAutomated safety check: PassMIT
Maui Authenticationdavidortinau/maui-skills175—~1.5kAutomated safety check: PassMIT
Microsoft Azure Webjobs Extensions Authentication Events Dotnetmicrosoft/skills3.1k5 repos~3.8kAutomated safety check: PassMIT
Authentication TracingSCStelz/security-investigator249—~8.6kAutomated safety check: PassMIT

Similar skills

  • Msal Client Credentials

    AzureAD/microsoft-authentication-library-for-dotnet

    Client Credentials Flow for service-to-service (daemon) authentication in MSAL.NET without user involvement

    1.5k GitHub stars~1.1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Maui Authentication

    davidortinau/maui-skills

    Add authentication to .NET MAUI apps. An agent skill from davidortinau/maui-skills.

    175 GitHub stars~1.5k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Authentication Tracing

    SCStelz/security-investigator

    A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.

    249 GitHub stars~8.6k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Implementing Google Workspace Sso Configuration

    mukul975/Anthropic-Cybersecurity-Skills

    Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Categories

Questions about Windows Hello

What does Windows Hello do?

Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate. Windows Hello is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Windows Hello for Business (WHfB) — passwordless, phishing-resistant authentication using a PIN or biometric backed by an asymmetric key or certificate.

When should I use Windows Hello?

Windows Hello fits situations like: FIDO2 security keys (use entra-id); CA policy authoring (use conditional-access-mfa); intune compliance baseline (use intune-device-mgmt).

How do I install Windows Hello in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a claude-code`. Or copy the skill folder (skills/windows-hello in vinayaklatthe/microsoft-security-skills) into .claude/skills/windows-hello in your project. Claude Code loads it when a task matches its description.

How do I install Windows Hello in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a codex`. Or copy the skill folder (skills/windows-hello in vinayaklatthe/microsoft-security-skills) into .agents/skills/windows-hello in your project. Codex loads it when a task matches its description.

Can I use Windows Hello in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill windows-hello -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/windows-hello, .gemini/skills/windows-hello, .github/skills/windows-hello and .opencode/skills/windows-hello in your project.

What does Windows Hello need to run?

SKILL.md names no scripts, command-line tools or credentials: Windows Hello is instructions for the agent only.

Does Windows Hello access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Windows Hello safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Windows Hello use?

Windows Hello is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Windows Hello use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Windows Hello?

Skills that share tags, products or a category with Windows Hello: Msal Client Credentials (AzureAD/microsoft-authentication-library-for-dotnet, 1.5k stars), Azure APIM Policy Authoring (thomast1906/github-copilot-agent-skills, 202 stars), Maui Authentication (davidortinau/maui-skills, 175 stars) and Microsoft Azure Webjobs Extensions Authentication Events Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Windows Hello?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.