Disable Windows Hello but not Windows Hello for Business by GPO

Posted by dirmhirn@reddit | sysadmin | View on Reddit | 4 comments

Hi,

Windows 10/11 offer as sign-in method Windows Hello with PIN/Fingerprint/Camera. Is it possible to disable Windows Hello, but enable Windows Hello for Business only, as soon as the device is ready for WHfB?

I tried to disable convenience pin, but it still shows the PIN option and I can enable it, although WHfB is not yet ready to provision. (Device is not Entry joined yet.)

anyone did this bevore?

We have to enable hybrid join for all devices first and then WhfB. But I'm worried some devices might fail and users enable Windows Hello instead of WH for Business.

br Dirm