Windows Hello for Business prompt after Hybrid Azure AD Joining Win 10 Device | WHFB disabled

%3CLINGO-SUB%20id%3D%22lingo-sub-1226395%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1226395%22%20slang%3D%22en-US%22%3EVery%20strange.%20I%20have%20exactly%20same%20setup%20but%20I%20don%E2%80%99t%20get%20your%20experience.%3CBR%20%2F%3EDo%20you%20have%20Security%20Baseline%20or%20Windows%20Config%20profile%20in%20place%20that%20somehow%20pushing%20the%20setting%3F%20There%20are%20multiple%20places%20that%20you%20can%20enable%20WHFB%20in%20Intune.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1226439%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1226439%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%26nbsp%3BI%20know%2C%20very%20odd.%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20devices%20are%20only%20becoming%20Hybrid%20Azure%20AD%20Joined%2C%20I'm%20not%20enrolling%20Windows%20devices%20into%20InTune.%26nbsp%3B%20If%20I%20check%20InTune%20devices%2C%20there's%20no%20devices%20showing%2C%20as%20I'd%20expect.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20not%20encountered%20this%20on%20other%20installations%20with%20the%20same%20scenario.%26nbsp%3B%20I'm%20wondering%20if%20it's%20something%20specific%20within%20the%20AD%20forest%20environment%20I'm%20deploying%20into%20causing%20this%20to%20occur%2C%20opposed%20to%20the%20Tenant%20side%20setting%20but%20can't%20see%20what.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EI%20checked%20security%20baselines%20and%20windows%20configs%20in%20InTune%20and%20there's%20nothing%20assigned.%26nbsp%3B%20However%2C%20I%20would%20only%20expect%20that%20to%20take%20effect%20if%20the%20devices%2Fdevices%20were%20InTune%20enrolled.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20only%20way%20forward%20have%20found%20so%20far%20is%20scoping%20a%20GPO%20which%20scopes%20the%20setting%20%3CSTRONG%3EUse%20Windows%20Hello%20for%20Business%26nbsp%3B%3C%2FSTRONG%3Eto%20%3CSTRONG%3EDisabled%26nbsp%3B%3C%2FSTRONG%3Eunder%26nbsp%3B%3CSTRONG%3EUser%20Configuration%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%3C%2FSTRONG%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJust%20looking%20at%20the%20logic%20as%20why%20when%26nbsp%3B%3CSTRONG%3EUse%20Windows%20Hello%20for%20Business%20%3C%2FSTRONG%3Eis%20set%26nbsp%3B%3CSTRONG%3ENot%20Configured%26nbsp%3B%3C%2FSTRONG%3Edevices%20are%20prompting%20the%20user%20to%20set-up%20a%20pin%20after%20domain%20login.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CBR%20%2F%3ESome%20example%20screenshots%20below.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1226470%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1226470%22%20slang%3D%22en-US%22%3EVery%20clear.%20Thought%20you%20had%20the%20devices%20enrolled%20to%20Intune.%3CBR%20%2F%3E%3CBR%20%2F%3ENot%20sure%20if%20you%20have%20Intune%20license%20but%20worth%20try%20to%20enroll%20the%20device%20with%20Intune%20and%20disable%20WHFB%20by%20Config%20profile%20and%20scope%20it%20to%20the%20computer.%20I%E2%80%99m%20presuming%20this%20scenario%20because%20you%20are%20certain%20no%20Local%20GPO%20applied%20to%20enable%20WHFB.%3CBR%20%2F%3E%3CBR%20%2F%3EMoe%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1226490%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1226490%22%20slang%3D%22en-US%22%3EThanks%20for%20the%20idea.%3CBR%20%2F%3E%3CBR%20%2F%3EI'm%20pretty%20certain%20that%20the%20Use%20Windows%20Hello%20for%20Business%20setting%20is%20set%20to%20Not%20Configured%20as%20standard%20for%20Win10%20devices.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20curious%20part%20is%20I%20haven't%20seen%20this%20issue%20before%20on%20other%20set-ups%20where%20HAADJ%20is%20enabled%20and%20WHFB%20is%20set%20to%20disabled%20or%20Not%20Configured%20under%20Windows%20Enrolment.%3CBR%20%2F%3E%3CBR%20%2F%3EI'm%20going%20to%20continue%20with%20amending%20the%20WHFB%20setting%20by%20domain%20GPO%20for%20the%20time%20being%2C%20as%20opposed%20to%20enrolling%20into%20InTune%20for%20modify%20the%20setting.%20They'll%20essentially%20achieve%20the%20same%20outcome.%3CBR%20%2F%3E%3CBR%20%2F%3EAny%20other%20ideas%20welcome%20as%20to%20the%20WHFB%20setup%20PIN%20comes%20up%20when%20'Use%20Windows%20Hello%20for%20Business'%20setting%20is%20set%20to%20'Not%20Configured'%20as%20standard%20for%20Win10%20devices.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1241261%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1241261%22%20slang%3D%22en-US%22%3E%3CP%3EManaged%20to%20shed%20some%20light%20on%20this.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20short%2C%20ignore%20the%20WHFB%20settings%20in%20InTune%20unless%20the%20device%20is%20MDM%20enrolled%20and%20managed%20by%20InTune.%26nbsp%3B%20Essentially%20this%20was%20the%20associated%20to%20a%20group%20policy%20via%20AD%20on%20premises%20which%20was%20already%20in%20place%20for%20the%20AD%20forest%2Fdomain.%3CBR%20%2F%3E%3CBR%20%2F%3EThere%20was%20a%20COMPUTER%20GP%20in%20place%20which%20set%26nbsp%3B%3CSTRONG%3E%22%3CFONT%20color%3D%22%233366FF%22%3EComputer%20Configuration%3C%2FFONT%3E%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%3C%2FSTRONG%3E%20to%26nbsp%3B%3CSTRONG%3EEnabled%3C%2FSTRONG%3E.%26nbsp%3B%20I%20imagine%20that%20somebody%20switched%20it%20to%20enabled%20thinking%20that%20would%20be%20nice%20to%20have.%3CBR%20%2F%3E%3CBR%20%2F%3EAfter%20enabling%20HAADJ%2C%20a%20device%20was%20becoming%20hybrid%20joined%2C%20and%20the%20subsequent%20login%20from%20a%20synced%20AD%20user%20resulted%20in%20a%20WHFB%20Set-Up%20PIN%20prompt.%3CBR%20%2F%3E%3CBR%20%2F%3EHad%20the%26nbsp%3B%3CSTRONG%3E%22%3CFONT%20color%3D%22%233366FF%22%3EComputer%20Configuration%3C%2FFONT%3E%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%3C%2FSTRONG%3E%26nbsp%3Bsetting%20been%20set%20to%26nbsp%3B%3CSTRONG%3ENot%20Configured%3C%2FSTRONG%3E%2C%20this%20wouldn't%20have%20arisen%20as%20an%20issue.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20a%20note%2C%20once%20we%20had%20set%20the%26nbsp%3B%3CSTRONG%3E%22%3CFONT%20color%3D%22%23339966%22%3EUser%20Configuration%3C%2FFONT%3E%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%26nbsp%3B%3C%2FSTRONG%3Eto%20%3CSTRONG%3EDisabled%3C%2FSTRONG%3E%2C%20that%26nbsp%3Btook%20priority%20over%20the%26nbsp%3B%3CSTRONG%3E%3CFONT%20color%3D%22%233366FF%22%3EComputer%20Configuration%3C%2FFONT%3E%3C%2FSTRONG%3E%20policy%20and%20the%20WHFB%20prompt%20didn't%20show.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1241264%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1241264%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EManaged%20to%20shed%20some%20light%20on%20this.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20short%2C%20ignore%20the%20WHFB%20settings%20in%20InTune%20unless%20the%20device%20is%20MDM%20enrolled%20and%20managed%20by%20InTune.%26nbsp%3B%20Essentially%20this%20was%20the%20associated%20to%20a%20group%20policy%20via%20AD%20on%20premises%20which%20was%20already%20in%20place%20for%20the%20AD%20forest%2Fdomain.%3CBR%20%2F%3E%3CBR%20%2F%3EThere%20was%20a%20COMPUTER%20GP%20in%20place%20which%20set%26nbsp%3B%3CSTRONG%3E%22%3CFONT%20color%3D%22%233366FF%22%3EComputer%20Configuration%3C%2FFONT%3E%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%3C%2FSTRONG%3E%20to%26nbsp%3B%3CSTRONG%3EEnabled%3C%2FSTRONG%3E.%26nbsp%3B%20I%20imagine%20that%20somebody%20switched%20it%20to%20enabled%20thinking%20that%20would%20be%20nice%20to%20have.%3CBR%20%2F%3E%3CBR%20%2F%3EAfter%20enabling%20HAADJ%2C%20a%20device%20was%20becoming%20hybrid%20joined%2C%20and%20the%20subsequent%20login%20(from%20a%20synced%20AD%20user)%20resulted%20in%20a%20WHFB%20Set-Up%20PIN%20prompt.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20the%26nbsp%3B%3CSTRONG%3E%22%3CFONT%20color%3D%22%233366FF%22%3EComputer%20Configuration%3C%2FFONT%3E%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%3C%2FSTRONG%3E%26nbsp%3Bsetting%20been%20set%20to%26nbsp%3B%3CSTRONG%3ENot%20Configured%3C%2FSTRONG%3E%2C%20this%20wouldn't%20have%20arisen%20as%20an%20issue.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20a%20note%2C%20once%20we%20had%20set%20the%26nbsp%3B%3CSTRONG%3E%22%3CFONT%20color%3D%22%23339966%22%3EUser%20Configuration%3C%2FFONT%3E%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%26nbsp%3B%3C%2FSTRONG%3Eto%20%3CSTRONG%3EDisabled%3C%2FSTRONG%3E%2C%20that%26nbsp%3Btook%20priority%20over%20the%26nbsp%3B%3CSTRONG%3E%3CFONT%20color%3D%22%233366FF%22%3EComputer%20Configuration%3C%2FFONT%3E%3C%2FSTRONG%3E%20policy%20and%20the%20WHFB%20prompt%20didn't%20show.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20lesson%20learnt%20is%20to%20check%20those%20GP%20settings%20in%20an%20AD%20on%20premises%20prior%20to%20mass%20syncing%20devices%20to%20be%20Hybrid%20Azure%20AD%20Joined.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1225511%22%20slang%3D%22en-US%22%3EWindows%20Hello%20for%20Business%20prompt%20after%20Hybrid%20Azure%20AD%20Joining%20Win%2010%20Device%20%7C%20WHFB%20disabled%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1225511%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20looking%20for%20some%20clarification%20on%20the%20behaviour%20around%20Windows%20Hello%20for%20Business%20after%20Hybrid%20Azure%20AD%20joining%20Windows%2010%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20recently%20enabled%20HAADJ%20in%20AAD%20Connect.%26nbsp%3B%20As%20expected%20first%20of%20all%2C%20the%20devices%20acquire%20a%20userCertificate%20attribute%20as%20part%20of%20the%20WorkplaceJoin%20schedule%20task%2C%20sync%20to%20AzureAD%20as%20part%20on%20the%20next%20AADConnect%20sync%20cycle%20and%20show%20up%20in%20the%20Azure%20AD%20tenant%20as%20a%20HAAD%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20issue%20I%20encounter%20is%20with%20the%20Windows%20Hello%20for%20Business%20prompt.%26nbsp%3B%20When%20a%20synced%20user%20logs%20in%2C%20they're%20prompted%20to%20setup%20a%20Windows%20Hello%20for%20Business%20PIN.%26nbsp%3B%20You%20can%20skip%20the%20process%20and%20continue%20but%20every%20subsequent%20login%20ask%20you%20to%20set-up%20a%20PIN%20which%20you%20can%20sync.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20devices%20are%20HAADJ%20but%20not%20enrolled%20into%20Intune%20for%20MDM.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20the%20AzureAD%20Portal%20under%26nbsp%3B%3CSTRONG%3EMicrosoft%20Intune%5CDevice%20Enrollment%5CWindows%20Enrollment%5CWindows%20Hello%20for%20Business%3C%2FSTRONG%3E%2C%20it%20was%20set%20as%26nbsp%3B%3CSTRONG%3ENot%20Configured.%26nbsp%3B%26nbsp%3B%3C%2FSTRONG%3EI%20also%20changed%20this%20to%26nbsp%3B%3CSTRONG%3EDisabled%3C%2FSTRONG%3E%2C%20but%20the%20users%20still%20get%20the%20prompt.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20only%20way%20forward%20I'm%20finding%20to%20deal%20with%20this%20is%20by%20setting%20the%20settings%20%3CSTRONG%3E%E2%80%9CUse%20Windows%20Hello%20for%20Business%E2%80%9D%20%3C%2FSTRONG%3Eunder%26nbsp%3B%3CSTRONG%3E%22User%20Configuration%5CAdministrative%20Templates%5CWindows%20Components%5CWindows%20Hello%20for%20Business%E2%80%9D%3C%2FSTRONG%3E%20to%20Disabled.%26nbsp%3B%20It%20was%20previously%20set%20to%26nbsp%3B%3CSTRONG%3ENot%20Configured.%26nbsp%3B%26nbsp%3B%3C%2FSTRONG%3EThis%20stops%20the%20setup%20PIN%20prompt%20coming%20up%20after%20login%2C%20however%2C%20notifications%20still%20appear%20in%20the%20notification%20area%20after%20login%20saying%20that%20%3CSTRONG%3EThe%20system%20is%20configured%26nbsp%3Bto%20use%20Windows%20Hello%20for%20Business%2C%26nbsp%3B%20Click%20here%20to%20setup%20you%20PIN.%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20do%20not%20get%20this%20behaviour%20in%20other%20environments%20where%20I%20have%20HAADJ%20configured%2C%20with%20seemingly%20the%20same%20settings.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEnd%20goal%20is%20wanting%20to%20retain%20HAADJ%20but%20disable%20all%20the%20prompts%20for%20setting%20up%20Windows%20Hello%20for%20Business.%26nbsp%3B%20Any%20ideas%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1225511%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Hello%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Contributor

Hello,

 

I'm looking for some clarification on the behaviour around Windows Hello for Business after Hybrid Azure AD joining Windows 10 devices.

 

I recently enabled HAADJ in AAD Connect.  As expected first of all, the devices acquire a userCertificate attribute as part of the WorkplaceJoin schedule task, sync to AzureAD as part on the next AADConnect sync cycle and show up in the Azure AD tenant as a HAAD device.

 

The issue I encounter is with the Windows Hello for Business prompt.  When a synced user logs in, they're prompted to setup a Windows Hello for Business PIN.  You can skip the process and continue but every subsequent login ask you to set-up a PIN which you can sync.

 

The devices are HAADJ but not enrolled into Intune for MDM.

 

In the AzureAD Portal under Microsoft Intune\Device Enrollment\Windows Enrollment\Windows Hello for Business, it was set as Not Configured.  I also changed this to Disabled, but the users still get the prompt.

 

I only way forward I'm finding to deal with this is by setting the settings “Use Windows Hello for Business” under "User Configuration\Administrative Templates\Windows Components\Windows Hello for Business” to Disabled.  It was previously set to Not Configured.  This stops the setup PIN prompt coming up after login, however, notifications still appear in the notification area after login saying that The system is configured to use Windows Hello for Business,  Click here to setup you PIN.

 

I do not get this behaviour in other environments where I have HAADJ configured, with seemingly the same settings.

 

End goal is wanting to retain HAADJ but disable all the prompts for setting up Windows Hello for Business.  Any ideas?

 

5 Replies
Highlighted
Very strange. I have exactly same setup but I don’t get your experience.
Do you have Security Baseline or Windows Config profile in place that somehow pushing the setting? There are multiple places that you can enable WHFB in Intune.
Highlighted

@Moe_Kinani I know, very odd. 

The devices are only becoming Hybrid Azure AD Joined, I'm not enrolling Windows devices into InTune.  If I check InTune devices, there's no devices showing, as I'd expect.

 

I have not encountered this on other installations with the same scenario.  I'm wondering if it's something specific within the AD forest environment I'm deploying into causing this to occur, opposed to the Tenant side setting but can't see what.


I checked security baselines and windows configs in InTune and there's nothing assigned.  However, I would only expect that to take effect if the devices/devices were InTune enrolled.

The only way forward have found so far is scoping a GPO which scopes the setting Use Windows Hello for Business to Disabled under User Configuration\Administrative Templates\Windows Components\Windows Hello for Business.

 

Just looking at the logic as why when Use Windows Hello for Business is set Not Configured devices are prompting the user to set-up a pin after domain login. 


Some example screenshots below.

Highlighted
Very clear. Thought you had the devices enrolled to Intune.

Not sure if you have Intune license but worth try to enroll the device with Intune and disable WHFB by Config profile and scope it to the computer. I’m presuming this scenario because you are certain no Local GPO applied to enable WHFB.

Moe
Highlighted
Thanks for the idea.

I'm pretty certain that the Use Windows Hello for Business setting is set to Not Configured as standard for Win10 devices.

The curious part is I haven't seen this issue before on other set-ups where HAADJ is enabled and WHFB is set to disabled or Not Configured under Windows Enrolment.

I'm going to continue with amending the WHFB setting by domain GPO for the time being, as opposed to enrolling into InTune for modify the setting. They'll essentially achieve the same outcome.

Any other ideas welcome as to the WHFB setup PIN comes up when 'Use Windows Hello for Business' setting is set to 'Not Configured' as standard for Win10 devices.
Highlighted

@Moe_Kinani 

 

Managed to shed some light on this.

In short, ignore the WHFB settings in InTune unless the device is MDM enrolled and managed by InTune.  Essentially this was the associated to a group policy via AD on premises which was already in place for the AD forest/domain.

There was a COMPUTER GP in place which set "Computer Configuration\Administrative Templates\Windows Components\Windows Hello for Business” to Enabled.  I imagine that somebody switched it to enabled thinking that would be nice to have.

After enabling HAADJ, a device was becoming hybrid joined, and the subsequent login (from a synced AD user) resulted in a WHFB Set-Up PIN prompt.

If the "Computer Configuration\Administrative Templates\Windows Components\Windows Hello for Business” setting been set to Not Configured, this wouldn't have arisen as an issue.

As a note, once we had set the "User Configuration\Administrative Templates\Windows Components\Windows Hello for Business” to Disabled, that took priority over the Computer Configuration policy and the WHFB prompt didn't show.

 

So lesson learnt is to check those GP settings in an AD on premises prior to mass syncing devices to be Hybrid Azure AD Joined.