Windows Hello not prompting for PIN

Tom Wrigglesworth 125 Reputation points
2024-01-09T14:17:06.7033333+00:00

Hello,

We are deploying WHfB to Windows 10 Pro devices, using Intune.

Devices are compatible to have this setup but users aren't getting prompted for a PIN, after the biometric is set.

The laptops that are having this issue are different models and all up-to-date.

Can we get some guidance on why this is happening?

Kind regards

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,823 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,569 questions
{count} votes

2 answers

Sort by: Most helpful
  1. glebgreenspan 2,245 Reputation points
    2024-01-09T18:09:18.3633333+00:00

    Hey Tom

    Did you try to follow these steps?

    1. Verify Windows Hello for Business settings: Ensure that the WHfB policy is correctly configured in Intune. Check the "Conditional Access" and "Windows Hello for Business" settings to make sure they align with your requirements.
    2. Check Windows Hello for Business deployment state: Confirm that the deployment state of WHfB is properly set in Intune. In some cases, if the deployment state is set to "Blocked," users may not be prompted for a PIN. Change it to "Active" if needed.
    3. Verify user account permissions: Ensure that the users have the necessary permissions to set up and use biometrics with WHfB. Users should have appropriate rights assigned through Azure AD or Active Directory, depending on your organization's configuration.
    4. Check biometric device settings: Confirm that the biometric devices (e.g., fingerprint scanners, etc.) are enabled and configured correctly on the devices. Check the device's manufacturer documentation or consult with your IT team to ensure the biometric devices are properly set up

    .5. Update device drivers: Make sure that the device drivers on the laptops are up-to-date. Outdated or incompatible drivers can cause issues with WHfB functionality. Check the device manufacturer's website for the latest drivers and update accordingly.

    1. Review Windows Hello for Business enrollment logs: Check the Event Viewer logs on the laptops for any error messages related to the WHfB enrollment process. Look for events related to fingerprint enrollment or Windows Hello. These logs can provide insights into any problems encountered during the setup.

  2. ZhoumingDuan-MSFT 17,085 Reputation points Microsoft External Staff
    2024-01-10T05:22:09.3266667+00:00

    @Tom Wrigglesworth,Thanks for posting in Q&A.

    From your description, I know you encountered an issue that users aren't getting prompted for a PIN, after the biometric was set.

    For the issue, please try to enable windows Hello Biometric Login on the affected device manually to see if it can work. After the policy is assigned to the device group, we can log one user to sync and get the policy and go to Settings > Accounts > Sign-in Options to set the biometric. Then restart the device to see if it can work.

    However, if it still failed, please collect the following information to clarify:

    How did we configure the configuration policy, Is it under Identity Protection? Could you get a screen shot of the detailed configuration?

    Please check the "Device status" to see if the policy is applied successfully.

    Please check if the policy is assigned to device group.

    Please check if there exist the errors in Event Viewer. Location: Event Viewer > Applications and Services logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostic-Provider > Admin.

    You can try to unassign the policy and reassign the policy to check whether can resolve the issue.

    Please try the above suggestion and if there's anything unclear, feel free to let us know.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.