Disable Windows Hello for students on Intune-managed devices

Schultz, Tricia 0 Reputation points
2026-09-23T17:58:55.7733333+00:00

Hello,

We are a K-12 educational institution using Microsoft Intune to manage student Windows devices.

We would like to completely disable Windows Hello for Business, including PIN setup, on all student-owned school devices. Our goal is to prevent students from creating or using Windows Hello PINs and require them to sign in using their assigned school account credentials only.

Could you provide:

  1. The recommended Intune configuration to disable Windows Hello for Business for student devices.
  2. Whether this should be configured through an Account Protection policy, Configuration Profile, Settings Catalog, or another policy type.
  3. Any additional settings that should be configured to prevent users from creating PINs after deployment.
  4. Guidance on removing existing Windows Hello PINs from devices that have already been enrolled.
  5. Any known impacts to Microsoft Entra ID authentication, Single Sign-On, or other Microsoft 365 services when Windows Hello is disabled.

Our environment consists of Windows devices managed through Microsoft Intune and Microsoft Entra ID.

Thank you for your assistance.

We did try the

Microsoft Security | Intune | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-09-23T17:59:18.6933333+00:00

    For Intune-managed student devices, the recommended approach is to disable Windows Hello for Business at the tenant level, then use targeted policies only for groups that should still have it, such as staff or teachers.

    1. Recommended Intune configuration
      1. In the Microsoft Intune admin center, go to Devices > By platform > Windows > Device onboarding > Enrollment.
      2. Select Windows Hello for Business.
      3. Set Configure Windows Hello for Business to disabled.
      4. Save the change.
      This is specifically called out as a common approach for schools so students are not prompted to set up multifactor authentication during sign-in.
    2. Which policy type to use
      • For a broad student-device disablement, use the tenant-wide Windows Hello for Business policy.
      • If Windows Hello for Business is needed for some users or devices later, use targeted policies, because targeted policies take precedence over the tenant-wide policy.
      • The Account protection profile (Preview) also includes Block Windows Hello for Business where:
        • Enabled = devices don’t provision Windows Hello for Business
        • Not configured or Disabled = devices provision Windows Hello for Business
      • Since that Account protection profile is marked deprecated in July 2024, the tenant-wide setting is the cleaner recommendation from the available guidance.
    3. Additional settings to prevent PIN creation after deployment
      • If disabling through Intune policies instead of relying only on the tenant-wide setting, enable the Enrollment Status Page (ESP) so devices receive the Windows Hello for Business policy before users reach the desktop.
      • This helps prevent users from being prompted before policy arrives.
      • Avoid creating conflicting local GPO or registry settings alongside MDM policy, because conflicts can cause unexpected results.
      • If registry-based deployment is used during provisioning or OS deployment, the documented values to disable Windows Hello for Business are:
        • CSP (device): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies → UsePassportForWork = 0
        • GPO (device): HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork → Enabled = 0
      Note: registry changes can affect sign-in behavior if applied incorrectly, so policy-based management is the safer approach.
    4. Removing existing Windows Hello PINs from already enrolled devices The available guidance covers how to stop provisioning and enrollment of Windows Hello for Business, but it does not provide a supported Intune procedure here for remotely removing existing PINs from devices that already have them configured.
    5. Known impacts to Microsoft Entra ID authentication, SSO, or Microsoft 365 services
      • Windows Hello for Business is enabled by default for Microsoft Entra joined devices, so disabling it stops that sign-in method from being provisioned.
      • Additional steps are required only when configuring single sign-on to on-premises resources with Windows Hello for Business credentials. Disabling Windows Hello for Business means that specific Windows Hello for Business credential path is not being used.
      • No other impact to Microsoft 365 services is described here.

    Also relevant for student environments:

    • It is typical for schools to disable Windows Hello for Business to avoid students being asked to set up MFA during sign-in.
    • During OOBE for a Microsoft Entra join without Intune, users can cancel the PIN screen and still reach the desktop without enrolling in Windows Hello for Business.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.