To create this GPO is pretty simple, just by creating a new GPO or you could reuse a existing GPO (Not the default GPO).
*Note: Windows Hello only works with Windows Server 2016 and Surface Pro, Windows 10
Here are the simple steps;
- At the Group Policy Management > Group Policy Objects > right click to create a new policy/edit the existing policy
- The image below is basically the policy to enable Windows Hello feature
- After this, remember to link the gpo to the OU that you wish it will take the gpo
- Remember to also do a “gpupdate /force” at both the server and computer side.
- Open cmd > type the command “gpupdate /force”
- There is a gpupdate function with one push, but you have to make sure that the user’s computer are connected.
- In the GPMC > select the OU > right click > select GPO Update policy
- This will update all the objects inside that particular OU
- In the GPMC > select the OU > right click > select GPO Update policy