Windows Hello for Business fallback configuration

testuser7 206 Reputation points
2022-11-13T14:19:24.217+00:00

Hello,

In case of Windows-Hello for Business signing into the laptop, we know that we can use biometrics like Fingerprint

If for some reason if the fingerprint reader is not accepting my already enrolled fingerprint then after couple of failed attempts I will be asked to put the PIN

Basically PIN is a fallback plan.

I would like to know, is there any way I can turn off the fallback method.
Of course user will be left out in such case.

Thanks.

Azure Active Directory
Azure Active Directory
An Azure enterprise identity service that provides single sign-on and multi-factor authentication.
14,747 questions
{count} votes

2 answers

Sort by: Most helpful
  1. JimmySalian-2011 31,901 Reputation points
    2022-11-13T14:51:31.51+00:00

    Hi testuser,

    I do realise your setup and hence I requested you to test on a single devices. However disabling is not recommended as per Microsoft as this will disable the Biometrecis too.

    259882-image.png

    Goodluck my friend.

    Hope this helps.
    JS

    ==
    Please Accept the answer if the information helped you. This will help us and others in the community as well.

    1 person found this answer helpful.

  2. JimmySalian-2011 31,901 Reputation points
    2022-11-13T14:32:53.12+00:00

    Hi,

    I think you can try this GPO settings:

    1.Navigate to Computer Configuration -> Administrative Templates -> System -> Logon
    2.Set the Turn on convenience PIN sign-in policy to Disabled, Apply.

    Try this one a single PC for a test and see how it goes.

    Hope this helps.
    JS

    ==
    Please Accept the answer if the information helped you. This will help us and others in the community as well.