Windows Hello for Business options currently unavailable

KuchJ 21 Reputation points
2020-12-21T18:14:02.093+00:00

Greetings Everyone, I am stock on this one and can't figure out why it won't work. I have gone through every walk through and settings and nothing seems to enable Hello Business. Background of the project, Server 2012 R2 server, used RSAT tools from my Windows 10 laptop to create the Domain Policy on the Domain controller to get the Hello for Business options. Here are some screen shots of what I have tried which I swear is everything. Thank you for the help!
49950-cmddp.jpg50064-hello1.jpg50102-hello2.jpg50103-userconfighello1.jpg49995-sign-in.jpg

Windows for business | Windows Server | User experience | Other
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

7 answers

Sort by: Most helpful
  1. Teemo Tang 11,471 Reputation points
    2020-12-22T06:54:27.727+00:00

    Clearing all the contents of the NGC folder
    path: C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc, you need to take ownership of this folder.
    Found a solution at https://social.technet.microsoft.com/Forums/en-US/84a0bd50-1360-4a94-bfb3-b049ecace521/pin-and-fingerprint-signin-options-unavailable-greyed-out-in-windows-10-1607-enterprise?forum=win10itprogeneral

    1. "Turn on Convenience PIN sign-in" policy must be enabled
    2. All 3 Policies under Computer Configuration\Administrative Templates\Windows Components\Windows Hello for Business\ must be in the state "Not configured". This was the piece that was missing, and not documented properly on Technet.
      Then, add the reg key mentioned above manually:
      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
      "AllowDomainPINLogon"=dword:00000001

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. KuchJ 21 Reputation points
    2020-12-22T15:20:41.097+00:00

    Greetings TeemoTang,
    Check my Ngc folder and it was all clear with nothing at all in it. The Convenience Pin Sign in I already had enabled in one of the pictures above but I triple checked and still enabled. I switched the Three Policies you suggested back to Not Configured and DWORD (64bit right I hope since I am running 64bit windows?) in my registry. Now the wait and see game. I did a gpupdate /force and a reboot of my PC but no changes yet. I will let you know the results for sure in a couple hours just to make sure. Thank you for your help!

    50522-image.png

    50502-image.png

    50318-image.png

    0 comments No comments

  3. KuchJ 21 Reputation points
    2020-12-22T18:01:09.283+00:00

    I figured with a GPupdate /force and a couple reboots, the new settings should be working but same results. :( Seems like it should be a simple thing but I am stumped.

    50490-image.png

    0 comments No comments

  4. Teemo Tang 11,471 Reputation points
    2020-12-25T08:02:08.53+00:00

    Very strange, please try the method here:
    In my case, I added a new user (Add someone else to this PC) on the Accounts page (Family & other users) by creating a new Microsoft account. I was allowed to set up the Windows Hello for this new user. The new user was set to Administrator. Then I logged out and logged in with the old Admin account. Finally Windows allowed me to set up Hello for the old Admin account!!!!
    Source:
    https://social.technet.microsoft.com/Forums/windows/en-US/8eade100-6ea8-4e84-a332-f733920cf974/fresh-install-of-windows-10-1903-windows-hello-face-this-option-is-currently-unavailable-click?forum=win10itprosecurity

    0 comments No comments

  5. KuchJ 21 Reputation points
    2020-12-28T17:20:50.177+00:00

    I will totally give that a shot. None of our accounts are set as local admins. Even me being the network admin but we have separate admin accounts when needed. I never thought of that and could see it totally working when set as a local admin. I will let you know the results when I get done testing it. Thank you for your help!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.