a customer of mine asked me if IDM 4.6 (UA and SSPR) can fit into "Microsoft Hello". I guess it is not possible because a Kerberos TGT (ticket-granting ticket) is not probably generated on background and only a Primary Refresh Token (PRT) is generated (which is used e.g. for the AD FS and Azure applications).

Do you have any experience with that?

Best Regards,