With Windows Hello for Business, the PIN is user-provided entropy used to load the private key in the Trusted Platform Module (TPM).The user must provide the entropy, the TPM-protected key, and the TPM that generated that key in order to successfully access the private key.
This enrollment profile biometrics data is device specific, is stored locally on the device, and does not leave the device or roam with the user. Some external fingerprint sensors store biometric data on the fingerprint module itself rather than on Windows device.
Also check this requirements for WHFB - windows-hello-biometric-requirements
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.