How to disable Windows Hello for Business PIN on AAD Joined laptop?

Hernando Torrealba 5 Reputation points
2024-01-18T19:47:21.96+00:00

Good afternoon, We're looking to have AAD joined computers, however, I'd like to know how to disable Windows Hello for Business PIN logon for AAD. We do not currently use Intune but would still like to have our PCs AAD joined. Thank you!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
Microsoft Security | Intune | Other
{count} vote

2 answers

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 17,165 Reputation points Microsoft External Staff
    2024-01-19T02:46:27.4333333+00:00

    @Hernando Torrealba,Thanks for posting in Q&A.

    From your description, I know you are looking for a way to disable Windows Hello for Business PIN on AAD Joined device.

    Based on my researching, we can use Group Policy to disable Windows Hello for Business.

    Here are some steps you can refer.

    1.Press win + R, type gpedit.msc and enter.

    2.Click Administrative Templates > Windows Components > Windows Hello for Business under User configuration and Computer Configuration and disable use Windows Hello for Business.

    3.Open CMD as admin and type certutil.exe -deleteHelloContainer to delete the Windows Hello for Business container.

    4.Restart the device.

    Please try above information, if there is any update, feel free to let me know. If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Iliyan Vasilev (Tek Experts) 0 Reputation points Microsoft External Staff
    2024-03-29T07:51:30.7466667+00:00

    This works and thank you for that !

    Is there a way to make this as a bulk operation or automatically disable this for Entra Joined devices?

    Thanks a lot


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.