question

BrianHFASPS avatar image
0 Votes"
BrianHFASPS asked JamesAndrewartha-8663 published

Use convenience pin on pure AAD joined device? Windows Hello for Business related

Short Version:
Does anyone know if it is possible to have a pure AAD joined device to use convenience pin and not be required to do identity verification?

Details:
I work at a school and give Surface Pro devices to students as young as 7 years old or 3rd grade. I want to enable them to use the Hello facial login options built into the Surface Pro. We currently can't use Windows Hello for Business since it requires enrollment via identity verification. Young children don't have a mobile device or phone to do this with. There is no facility to do bulk enrollment for situations like this. (At least no one can tell me one for the last three years.) My workaround for the last few years is to join to local AD and enable via GPO convenience pin. Then I set the WHfB to Not Configured. This allows local PIN where as disabled setting prevents it.

Do to the needs of potential continuing distance learning I attempting again to fully transition to pure AAD rather than Hybrid-AAD join. I am finding that even with WHfB in a Not Configured state the user is told that the organization requires the use of it.

More details

Any other suggestions?

Brian Hoyt
Director of IT
French American School of Puget Sound


mem-intune-device-configurationsmem-intune-enrollment
· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Please understand that this issue is more related to Azure AD not Intune. Therefore, it is better to post a ticket with Azure AD tag so that the ticket can be followed by Azure AD team.
Also, based on my research, a user cannot create a convenience PIN in Windows 10 Version 1607 and later version when the Use Convenience PIN and Use Windows Hello for Business policies are both enabled unless the device is joined to Azure Active Directory in some way (for example, it is either Azure AD-joined or has the Computer Configuration\Administrative Templates\Windows Components\device registration\Register domain joined computers as devices policy enabled).

0 Votes 0 ·

Thanks for the reply. The settings for Windows Hello for Business, enrollment behavior and the configuration profiles to enable convenience PIN are all managed in Intune. AAD is the authentication mechanism but not what defines how the device works. My question is how to disable WHfB without totally disabling biometrics and simultaneously enable convenience PIN. The detail of why due to issues of AAD identity management were just for context.

I have found that I can enable convenience PIN via an ADMX configuration profile. I can also disable WHfB it seems to a select set of users. The challenge for me is I can't find a way to enable biometrics.

12881-image.png


It seems I might be able to do with ADMX ingestion but I am having challenges figuring it out.

These devices will be AAD joined.

1 Vote 1 ·
image.png (28.3 KiB)

You're out of luck. Convenience PINs aren't supported for pure AAD accounts: https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-faq#can-i-use-a-convenience-pin-with-azure-ad

It is currently possible to set a convenience PIN on Azure Active Directory Joined or Hybrid Active Directory Joined devices. Convenience PIN is not supported for Azure Active Directory user accounts. It is only supported for on-premises Domain Joined users and local account users.

0 Votes 0 ·

0 Answers