@Pavel yannara Mirochnitchenko, Thanks for posting in Q&A.
According to your description, I know that you want to enable WHFB for specific group users.
Based on my researching, there two ways to enable/disable WHFB, one is in enrollment stage, another is after enrollment stage. However, when you enable WHFB in enrollment stage, it can only assign to all users,
To enable WHFB and assign it to specific users’ group, you can consider create Account protection profile to enable WHFB which will occur after the enrollment. Here are some steps you can refer:
- Go to Microsoft Intune center > Endpoint security > Account protection > Create policy > Select Platform Windows 10 and later, select Account protection(Preview)
- Enter the policy name and click next > in the Configuration settings configure Block Windows Hello for Business Disable and other settings > In Assignment page assign it to specific users' group.
Hope this can be helpful.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.