- This topic has 2 replies, 2 voices, and was last updated 6 years ago by
Weekend Wiki.
- Post
-
- March 12, 2019 at 5:26 pm
Weekend WikiKeymasterHow to Disable Windows Hello PIN, Face ID, and Biometric (Fingerprint) Login in Microsoft Intune
Disabling Windows Hello PIN, Face ID, and Biometric logins (like Fingerprint authentication) can be crucial for organizations with strict security policies or compliance requirements. Microsoft Intune allows administrators to manage these settings across all managed devices in the organization.
Here’s a step-by-step guide to disabling Windows Hello features, including PIN, Face ID, and Fingerprint authentication, using Device Configuration Profiles in Intune.
Step 1: Create a Configuration Profile in Intune
- Log in to the Microsoft Intune Admin Center at https://endpoint.microsoft.com.
- Navigate to Devices → Configuration Profiles.
- Click + Create Profile.
- Choose Windows 10 and later (or the appropriate platform).
- Under Profile Type, select Device Restrictions.
- Click Create.
Step 2: Disable Windows Hello Features
- In the Profile Name field, enter a name (e.g., “Disable Windows Hello Features”).
- Under Configuration Settings, scroll down to find the Identity and Sign-in settings.
- Configure the following options:
- Windows Hello for Business: Set to Disabled to prevent the use of PIN, Face ID, and Fingerprint.
- Use Windows Hello for Business: Set to Disabled to completely turn off Windows Hello.
- Allow Fingerprint: Set to Disabled to prevent the use of fingerprint authentication.
- Allow Face Recognition: Set to Disabled to turn off Face ID login.
- Allow PIN Sign-in: Set to Disabled to disable Windows Hello PIN.
This will disable all Windows Hello features, including PIN, Face ID, and Fingerprint authentication.
Step 3: Assign the Profile to Devices
- After configuring the settings, click Next to proceed to the Assignments section.
- Choose the target device groups or user groups you want this policy to apply to.
- Click Next to review the settings and then click Create to deploy the profile.
Step 4: Monitor the Deployment
- Go to Devices → Monitor → Device Configuration to check the deployment status.
- Confirm that the policy has been applied successfully to the target devices.
Step 5: Verify the Settings on End Devices
- Once the policy is deployed, verify the changes on a target device by attempting to set up or use Windows Hello PIN, Face ID, or Fingerprint authentication.
- Windows Hello PIN: Go to Settings → Accounts → Sign-in Options. Ensure that the PIN option is unavailable.
- Face ID and Fingerprint: Go to Settings → Accounts → Sign-in Options and confirm that Face Recognition and Fingerprint are not available.
Step 6: Testing
Test the settings on one or more devices to ensure the following:
- PIN, Face ID, and Fingerprint login options are removed from Sign-in Options.
- Users can no longer enroll their biometrics (Face or Fingerprint) for authentication.
- If users attempt to access or enroll Windows Hello features, they should see a message indicating that the feature is disabled by your organization.
Conclusion
By using Microsoft Intune’s Device Configuration Profiles, you can easily disable Windows Hello PIN, Face ID, and Fingerprint login across all managed devices in your organization. This provides an added layer of security and control, ensuring that only your preferred methods of authentication are available to users.
- Replies
-
- March 12, 2019 at 5:51 pm
Weekend WikiKeymasterDe qui dolor sint illum ad si ex velit doctrina, nulla commodo officia, veniam laborum in coniunctione, illum pariatur ut illum quid, te anim fabulas philosophari, vidisse est culpa ea ita quem si labore. Fore ex deserunt ita ut litteris domesticarum, cernantur quo eram non aliqua ita id irure fabulas. Et varias concursionibus, hic cernantur instituendarum. In nulla fore legam excepteur.- March 12, 2019 at 7:02 pm
Weekend WikiKeymasterNostrud irure excepteur mandaremus ita malis praetermissum pariatur fugiat possumus a te noster nescius aliquip, pariatur sint tempor eu iis an legam fabulas, non multos incididunt, duis firmissimum cernantur fore litteris, quis te e magna tempor.
- You must be logged in to reply to this topic.