Use convenience pin on pure AAD joined device? Windows Hello for Business related

Brian Hoyt 91 Reputation points
2020-07-16T02:02:03.137+00:00

Short Version:
Does anyone know if it is possible to have a pure AAD joined device to use convenience pin and not be required to do identity verification?

Details:
I work at a school and give Surface Pro devices to students as young as 7 years old or 3rd grade. I want to enable them to use the Hello facial login options built into the Surface Pro. We currently can't use Windows Hello for Business since it requires enrollment via identity verification. Young children don't have a mobile device or phone to do this with. There is no facility to do bulk enrollment for situations like this. (At least no one can tell me one for the last three years.) My workaround for the last few years is to join to local AD and enable via GPO convenience pin. Then I set the WHfB to Not Configured. This allows local PIN where as disabled setting prevents it.

Do to the needs of potential continuing distance learning I attempting again to fully transition to pure AAD rather than Hybrid-AAD join. I am finding that even with WHfB in a Not Configured state the user is told that the organization requires the use of it.

More details

Any other suggestions?

Brian Hoyt
Director of IT
French American School of Puget Sound

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,733 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,258 questions
{count} votes