I can give you some details regarding your use case :
- Windows Hello for Business (WHfB)
If you only have 2016 domain controllers you should go to the hybrid key trust scenario - Computer management
You should go hybrid azure ad like that you can still use your existing GPOs and it will be mandatory for WHfB hybrid - Azure AD Connect
If you don't have a requirement to have authentication regarding cloud app to happen onpremise you should go for Password Hash Sync with seamless SSO