GPO: Enable Windows Hello (PIN and Biometrics) on Domain PCs
Create a new GPO linked to the computers' OU with these settings.
Computer Configuration > Policies > Administrative Templates > System > Logon
- Turn on convenience PIN sign-in: Not configured
Computer Configuration > Policies > Administrative Templates > Windows Components > Windows Hello for Business
- Use Windows Hello for Business: Enabled
- Use biometrics: Enabled
- Turn off smart card emulation: Disabled
- Configure device unlock factors: Disabled
Apply and check on a client:
gpupdate /force
dsregcmd /status
Note: Windows Hello for Business needs a trust model (cloud Kerberos trust, key trust or certificate trust) for domain users to enroll. In a pure on-premises AD without it, set Turn on convenience PIN sign-in to Enabled to get a classic PIN instead.