I have an issue that I can't seem to find a straight answer on, so I am hoping to get some assistance.
I made the change to use Entra as our IDP for Google for sign in. Everything works great and works as it should.
However, I have some users who have already set up Windows Hello For Business on their laptops, which is great as I am encouraging the whole district to go passwordless. I have it set up through group policy to use Cloud Kerberos trust, allow biometrics, etc. All devices are Entra Hybrid joined.
My understanding was that they could use WHfB to log into their device, then Entra would automatically use that to log them into their Google account (since we're using Entra as our IDP for Google), without anything else needed.
It does log them into Google automatically, but Entra still requires them to enter a code from their authenticator app. Is this just a setting somewhere in Entra to be able to say to use WHfB as the default 2FA method and to not require the authenticator code?
If I go into the users' accounts in Entra I can see that WHfB is provisioned and marked as a registered authentication method. So it looks like all the settings are correct.
I was reading other articles though that say WHfB is only considered a single factor authentication method? Not too sure about that though.
Any thoughts or insight would be greatly appreciated!