Forum Discussion
Marc_Laf
Apr 14, 2023Iron Contributor
Azure AD Joined device is not honoring Windows Hello for Business Config Policy from Intune
With the availability of Cloud Kerberos Trust we are now able to deploy WHfB to our Hybrid workforce but we do have a handful of Azure AD Joined devices that we also need to deploy to, all of these d...
johna8
Jun 06, 2023Copper Contributor
We're stuck in the same situation as well. AADJ joined - tenant wide setting disabled. Various device policies to specify WHfB along with an adjusted PIN policy but still picks up the default PIN policies.
In the interim we are doing a work around to write the amended PIN policy to the hive below - HKLM\SOFTWARE\Policies\Microsoft\PassportForWork\PINComplexity and this appears to inherit the PIN settings we required. (This is where the local gpo policies write so we decided on this location).