nerdexam
Microsoft

MS-900 · Question #174

You have Windows 10 Pro devices that are joined to an Active Directory domain. You plan to create a Microsoft 365 tenant and to upgrade the devices to Windows 10 Enterprise. You are evaluating…

The correct answer is A. Microsoft Azure Active Directory (Azure AD) C. Microsoft Intune enrollment. Windows Hello for Business requires specific infrastructure components to enable SSO to Microsoft 365 services. For a cloud or hybrid deployment targeting Microsoft 365, Azure AD and Intune are foundational prerequisites.

Submitted by ahmad_uae· Mar 5, 2026Describe Microsoft 365 apps and services

Question

You have Windows 10 Pro devices that are joined to an Active Directory domain. You plan to create a Microsoft 365 tenant and to upgrade the devices to Windows 10 Enterprise. You are evaluating whether to deploy Windows Hello for Business for SSO to Microsoft 365 services. What are two prerequisites of the deployment? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • AMicrosoft Azure Active Directory (Azure AD)
  • Bsmartcards
  • CMicrosoft Intune enrollment
  • DTPM-enabled devices
  • Ecomputers that have biometric hardware features

How the community answered

(61 responses)
  • A
    82% (50)
  • B
    3% (2)
  • D
    10% (6)
  • E
    5% (3)

Why each option

Windows Hello for Business requires specific infrastructure components to enable SSO to Microsoft 365 services. For a cloud or hybrid deployment targeting Microsoft 365, Azure AD and Intune are foundational prerequisites.

AMicrosoft Azure Active Directory (Azure AD)Correct

Azure Active Directory is a mandatory prerequisite for Windows Hello for Business when targeting Microsoft 365 SSO, as it provides the identity platform for device registration, authentication, and token issuance that WHfB relies on for cloud-based single sign-on.

Bsmartcards

Smartcards are a separate authentication technology and are not a prerequisite for Windows Hello for Business; WHfB is specifically designed to replace smartcard and password-based authentication with key-based or certificate-based credentials.

CMicrosoft Intune enrollmentCorrect

Microsoft Intune enrollment is required to manage and deploy Windows Hello for Business policies to devices in a Microsoft 365 scenario, as Intune serves as the MDM authority that provisions WHfB settings and enforces the configuration across enrolled devices.

DTPM-enabled devices

While a TPM chip enhances security for Windows Hello for Business by providing hardware-backed key storage, it is not a strict mandatory prerequisite for deployment, as WHfB can function in software-based key storage mode on devices without a TPM.

Ecomputers that have biometric hardware features

Biometric hardware (such as fingerprint readers or IR cameras) is optional for Windows Hello for Business, as the solution also supports PIN-based authentication, meaning biometric sensors are a feature enhancement but not a deployment prerequisite.

Concept tested: Windows Hello for Business prerequisites for Microsoft 365 SSO

Source: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-prerequisites

Topics

#Windows Hello for Business#Azure AD#Intune enrollment#SSO

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice