Skip to main content

Windows Hello Profile

Windows Hello is a more secure way to get instant access to Windows 10 devices using biometric gestures (fingerprint/facial recognition) or PIN gesture. This profile allows admins to configure fingerprint/facial recognition or set a PIN on the enrolled devices that help the users to get access to the applications, websites, and networks.

note

The device must be Microsoft Entra ID (formerly Azure Active Directory) Joined and enrolled through Windows EMM or Dual Enrollment mode. The device should support Windows Hello for this feature to work.

To configure fingerprint/facial recognition or set a PIN on the enrolled device(s), follow these steps:

  1. Navigate to SureMDM Web Console > Profiles > Windows > Add > Windows Hello > Configure.

  2. Enter a Profile Name.

  3. Configure Windows Hello settings and click Save.

SettingsDescription
Windows HelloAllow the use of Windows Hello for business.
Use BiometricsAllow the use of biometric gestures such as fingerprint or face recognition instead of PIN gesture.
TPMEnable this option to disallow TPM (Trusted Protection Module revision 1.2) from using with Windows Hello profile.
Minimum Pin LengthEnter the minimum number of digits for setting a PIN.
Maximum Pin LengthEnter the maximum number of digits for setting a PIN.
DigitsSet the usage of digits (Allowed/Required/Not Allowed).
Upper Case LettersConfigure the use of upper case letters (Allowed/Required/Not Allowed).
Lower Case LetterConfigure the use of lower case letters (Allowed/Required/Not Allowed).
Special CharactersConfigure the use of special characters (Allowed/Required/Not Allowed).
Use Security Key For Sign InUse this option for the users to sign-in to their device with FIDO security key.

The newly created profile will be listed under the Profiles section.

  1. Go back to the Home tab and select the Windows device(s) or group(s).

  2. Click Apply to launch the Apply Job/Profile To Device prompt.

  3. Select the profile under All Jobs/Profiles.

  4. Click Apply in the Apply/Profile To Device prompt.