Forum Discussion

underQualifried's avatar
underQualifried
Brass Contributor
Oct 23, 2025

Disabling PIN-based login on Entra-joined PCs

Hi guys. Yesterday I took two machines off the domain and Entra joined them. The goal was 1) remove their access to domain resources 2) have tenant users login to the machine and get enriched tokens every time. this works as desired. The problem is every user gets prompted to set a pin. these are both shared secondary/tertiary PC's -  there is no point to having a 6 digit PIN on them. 

I thought the new Authentication Methods tools had controls for this, but apparently not.  A script was run to change certain related Reg Keys (by my onsite tech) but this had no change on reboot. 

textreg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork" /v Enabled /t REG_DWORD /d 0 /freg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork" /v DisablePostLogonProvisioning /t REG_DWORD /d 1 /f


HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork Enabled key was set to 0, and DisablePostLogonProvisioning was set to 1. These are from various help threads I found here and other resources. Unfortunately, they do not work. 

 

Not sure what to do here. I've read there are InTune controls for this - but I don't really have the time to work out WindowsPC ennrollment profiles for 2 machines. The site has InTune, but only for iOS mobile management. Thoughts? 

 

 

1 Reply

  • AladinH's avatar
    AladinH
    Brass Contributor

    Hi underQualifried​,

    Windows Hello for Business (PIN) is controlled by Entra ID and Intune, not local keys.

    To disable the PIN prompt:

    Option 1 (recommended):

    Go to Entra admin center > Protection > Authentication methods > Windows Hello for Business > Disable for all or specific users.

    https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-passwordless-disable 

    Option 2 (if using Intune):

    Create a policy under Devices > Configuration profiles > Identity protection > Configure Windows Hello for Business > Disabled

    https://learn.microsoft.com/en-us/mem/intune/protect/identity-protection-configure 

    Registry edits only apply to on-prem or hybrid devices - they won’t stop PIN setup on Entra-joined PCs.

Resources