GPO: Enable Windows Hello (PIN and Biometrics) on Domain PCs

Create a new GPO linked to the computers' OU with these settings.

Computer Configuration > Policies > Administrative Templates > System > Logon

  • Turn on convenience PIN sign-in: Not configured

Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Hello for Business

  • Use Windows Hello for Business: Enabled
  • Use biometrics: Enabled
  • Turn off smart card emulation: Disabled
  • Configure device unlock factors: Disabled

Apply and check on a client:

gpupdate /force
dsregcmd /status

Note: Windows Hello for Business needs a trust model (cloud Kerberos trust, key trust or certificate trust) for domain users to enroll. In a pure on-premises AD without it, set Turn on convenience PIN sign-in to Enabled to get a classic PIN instead.

Written by Daniel Ruiz Peláez, Systems & Infrastructure Engineer (Linux, VMware, Proxmox, Active Directory, networking and security). These are notes from real problems I have solved.

← Back to all posts