Hello @ajm-b ,
Thank you for posting here.
Based on my knowledge, Windows hello for business needs AAD environment, so you have AAD environment?
If so, you have deployed Windows Hello for Business for end users on one system, but you want end users to use Windows Hello for Business on whatever pc they are using.
Windows hello for business, which is configured by Group Policy or MDM policy, if domain administrator did not configured Windows Hello for Business for the devices by Group Policy or MDM policy, end users should be not able to use Windows Hello for Business.
If anything I misunderstood, please feel free to let us know.
Best Regards,
Daisy Zhou