How to disable Windows Hello for Business PIN on AAD Joined laptop?

Hernando Torrealba 0 Reputation points
2024-01-18T19:47:21.96+00:00

Good afternoon, We're looking to have AAD joined computers, however, I'd like to know how to disable Windows Hello for Business PIN logon for AAD. We do not currently use Intune but would still like to have our PCs AAD joined. Thank you!

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,247 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,266 questions
{count} votes

2 answers

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 13,965 Reputation points Microsoft Vendor
    2024-01-19T02:46:27.4333333+00:00

    @Hernando Torrealba,Thanks for posting in Q&A.

    From your description, I know you are looking for a way to disable Windows Hello for Business PIN on AAD Joined device.

    Based on my researching, we can use Group Policy to disable Windows Hello for Business.

    Here are some steps you can refer.

    1.Press win + R, type gpedit.msc and enter.

    2.Click Administrative Templates > Windows Components > Windows Hello for Business under User configuration and Computer Configuration and disable use Windows Hello for Business.

    3.Open CMD as admin and type certutil.exe -deleteHelloContainer to delete the Windows Hello for Business container.

    4.Restart the device.

    Please try above information, if there is any update, feel free to let me know. If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Iliyan Vasilev (Tek Experts) 0 Reputation points Microsoft Vendor
    2024-03-29T07:51:30.7466667+00:00

    This works and thank you for that !

    Is there a way to make this as a bulk operation or automatically disable this for Entra Joined devices?

    Thanks a lot


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.