I am the admin for a small business (~30 machines running a mix of Windows 10 and 11 Home editions). I am attempting to migrate towards passwordless sign on for key users using a Yubikey 5 NFC, but have run into a snag and am unsure of how best to proceed. Enabling Windows Hello seems to require either a Microsoft account, or Active Directory. We currently pay for Microsoft 365 for business, which apparently are not Microsoft accounts for the purposes of Windows login. My question is whether allowing users to use work emails as "Microsoft accounts" is supposed to by achieved by Azure Active directory. As in, is the intent that businesses looking to have employees do single sign on with work email pay for Azure Active directory? I just want to make sure that's the service I need to be looking at.