Password-less Authentication — Windows Hello & Intune MFA
Password-less Authentication is a service for organizations that want to implement multi-factor, password-less PC authentication using Microsoft Windows Hello and Microsoft Intune. IT Partner discusses authentication requirements, selects the appropriate authentication solution, configures Microsoft Intune profiles, devices, and authentication policy, provides user self-setup instructions, and includes break-fix support for the solution within two (2) weeks.
What this engagement is
Traditional password policies that rely on stronger complexity rules and frequent password changes can make work harder for employees while still falling short of current cybersecurity needs. This service helps the client implement a multi-factor, password-less authentication approach based on Microsoft Windows Hello and Microsoft Intune, so employees can use two-factor PC authentication without needing to use a password.
Success criteria
What you receive
How the work unfolds
Discussion of the requirements for the user authentication process with the client
Choosing the appropriate authentication solution
Configuration of user profiles and devices in Microsoft Intune
Configuration of authentication policy in Microsoft Intune for a test group
Testing on a limited number of devices
Implementation of the solution for all employees
Technical support
Prerequisites
Who does what
IT Partner
- Discussion of the requirements for the user authentication process with the client
- Choosing the appropriate authentication solution
- Configuration of user profiles and devices in Microsoft Intune
- Configuration of authentication policy in Microsoft Intune
- Providing self-setup instructions of the workstation interaction with a specific authentication device for the users
- Break-fix for the solution within two (2) weeks
Your team
- Informing users about changes
- Providing access to Azure management
- Providing remote access to workstations, if necessary
- The final configuration of each device (must be done by the employee-owner of the workstation)
What's not included
Frequently asked questions
What is IT Partner’s Password-less Authentication service?
Password-less Authentication is a $900 implementation service that helps organizations deploy multi-factor, password-less PC sign-in using Microsoft Windows Hello and Microsoft Intune. IT Partner reviews authentication requirements, selects an appropriate authentication approach, configures Intune profiles, devices, and authentication policy, and provides user self-setup instructions.
What business problem does this password-less authentication service solve?
This service helps reduce reliance on traditional passwords, because stronger complexity rules and frequent password changes can make work harder without fully addressing modern security needs. The goal is to allow employees to use two-factor PC authentication without needing to use a password.
What is included in the Password-less Authentication service?
The service includes a requirements discussion, selection of the appropriate authentication solution, configuration of user profiles and devices in Microsoft Intune, and configuration of authentication policy in Intune. It also includes user self-setup instructions for workstation interaction with the authentication device and break-fix support for the solution within two weeks.
What is not included in this service?
The service does not include the initial setup of Microsoft Intune, purchasing licenses, user training, or Entra ID configuration if the company uses only on-premises Active Directory. If your organization does not already use Microsoft Intune, its configuration can be ordered separately.
How long does the Password-less Authentication implementation take?
The stated duration for this service is one week. The engagement includes requirements review, solution selection, Intune configuration, test group policy configuration, limited device testing, employee-wide implementation, and technical support.
How much does the Password-less Authentication service cost?
The listed price for IT Partner’s Password-less Authentication service is $900. This price applies to the defined service scope, so any work outside that scope, such as initial Microsoft Intune setup or license purchasing, should be confirmed separately with IT Partner.
What Microsoft licensing or subscriptions are required before starting?
The prerequisites include a Microsoft Enterprise Mobility + Security subscription, Azure Active Directory or a hybrid identity environment, and devices added to Microsoft Intune. These prerequisites matter because the service configures password-less authentication through Microsoft Intune and depends on the identity and device management environment being in place.
Do all devices need to be enrolled in Microsoft Intune?
Yes, all configured devices must be added to Microsoft Intune before they can be included in this service. This is required because IT Partner configures user profiles, devices, and authentication policy in Microsoft Intune.
Can this service be used if we only have on-premises Active Directory?
Not as a complete in-scope implementation, because the prerequisites require Azure Active Directory or a hybrid environment. Entra ID configuration is specifically not included if the company uses only on-premises Active Directory, so that requirement should be addressed separately before or alongside the project.
What happens during the implementation process?
IT Partner first discusses authentication requirements with the client and chooses the appropriate authentication solution. The team then configures Microsoft Intune profiles, devices, and authentication policy, applies policy to a test group, performs limited device testing, and proceeds to employee-wide implementation.
Is the solution tested before being rolled out to all employees?
Yes, the implementation plan includes authentication policy configuration for a test group and testing on a limited number of devices. This staged approach helps validate the configuration before employee-wide implementation.
What are the success criteria for this service?
The service is considered successful when Microsoft Intune is configured to allow employees to use two-factor PC authentication without requiring a password. A second success criterion is that employees have successfully applied and are using the new authentication method.
What responsibilities does IT Partner handle?
IT Partner handles the authentication requirements discussion, authentication solution selection, Microsoft Intune profile and device configuration, Intune authentication policy configuration, user self-setup instructions, and two weeks of break-fix support. These responsibilities are limited to the service scope and assume the required Microsoft environment is already available.
What responsibilities does the client have during the engagement?
The client is responsible for informing users about the changes, providing access to Azure management, and providing remote access to workstations if needed. The client is also responsible for the final configuration of each device, which must be completed by the employee-owner of the workstation.
Will IT Partner train our users on the new sign-in method?
Formal user training is not included in this service. IT Partner does provide self-setup instructions for users, but broader training or change-management activities would need to be handled by the client or scoped separately.
Will this service cause downtime for employees?
The service content does not specify expected downtime. Because the implementation includes test group configuration, limited device testing, and employee-wide rollout, the business impact should be reviewed with IT Partner based on the number of devices, user readiness, and remote access requirements.
What support is included after the configuration is completed?
IT Partner includes break-fix support for the password-less authentication solution within two weeks. This support is for issues related to the implemented solution and does not expand the scope to items such as new Intune deployment, license procurement, or formal user training.
Who performs the final setup on each employee workstation?
The final configuration of each device must be done by the employee-owner of the workstation. IT Partner provides self-setup instructions so users can complete the workstation interaction with the specific authentication device.
Who manages the Password-less Authentication service engagement?
The listed service manager for Password-less Authentication is Roman Sotnik. Prospective buyers should confirm scheduling, readiness, and any environment-specific questions with IT Partner before starting the engagement.