Other Intune-related topics, including unsupported scenarios and platform-specific behaviors
For Intune-managed student devices, the recommended approach is to disable Windows Hello for Business at the tenant level, then use targeted policies only for groups that should still have it, such as staff or teachers.
- Recommended Intune configuration
- In the Microsoft Intune admin center, go to Devices > By platform > Windows > Device onboarding > Enrollment.
- Select Windows Hello for Business.
- Set Configure Windows Hello for Business to disabled.
- Save the change.
- Which policy type to use
- For a broad student-device disablement, use the tenant-wide Windows Hello for Business policy.
- If Windows Hello for Business is needed for some users or devices later, use targeted policies, because targeted policies take precedence over the tenant-wide policy.
- The Account protection profile (Preview) also includes Block Windows Hello for Business where:
- Enabled = devices don’t provision Windows Hello for Business
- Not configured or Disabled = devices provision Windows Hello for Business
- Since that Account protection profile is marked deprecated in July 2024, the tenant-wide setting is the cleaner recommendation from the available guidance.
- Additional settings to prevent PIN creation after deployment
- If disabling through Intune policies instead of relying only on the tenant-wide setting, enable the Enrollment Status Page (ESP) so devices receive the Windows Hello for Business policy before users reach the desktop.
- This helps prevent users from being prompted before policy arrives.
- Avoid creating conflicting local GPO or registry settings alongside MDM policy, because conflicts can cause unexpected results.
- If registry-based deployment is used during provisioning or OS deployment, the documented values to disable Windows Hello for Business are:
- CSP (device):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies→UsePassportForWork=0 - GPO (device):
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork→Enabled=0
- CSP (device):
- Removing existing Windows Hello PINs from already enrolled devices The available guidance covers how to stop provisioning and enrollment of Windows Hello for Business, but it does not provide a supported Intune procedure here for remotely removing existing PINs from devices that already have them configured.
- Known impacts to Microsoft Entra ID authentication, SSO, or Microsoft 365 services
- Windows Hello for Business is enabled by default for Microsoft Entra joined devices, so disabling it stops that sign-in method from being provisioned.
- Additional steps are required only when configuring single sign-on to on-premises resources with Windows Hello for Business credentials. Disabling Windows Hello for Business means that specific Windows Hello for Business credential path is not being used.
- No other impact to Microsoft 365 services is described here.
Also relevant for student environments:
- It is typical for schools to disable Windows Hello for Business to avoid students being asked to set up MFA during sign-in.
- During OOBE for a Microsoft Entra join without Intune, users can cancel the PIN screen and still reach the desktop without enrolling in Windows Hello for Business.