How to Enable or Disable Windows Hello Biometrics for Domain Users
Windows Hello biometrics let you sign in to your Windows 11 work or school PC using your face, fingerprint, or a PIN instead of a standard password.
Workplace networks sometimes block facial recognition and fingerprint sign-ins for security reasons, forcing you to use a traditional password instead. You can check your current setup or follow your company network rules to manage these sign-in choices on your computer.
Configure Windows Hello biometrics for domain users via Group Policy Editor or Registry Editor. Navigate to Administrative Templates Windows Components Biometrics in Group Policy, then adjust the “Allow domain users to log on using biometrics” setting. Alternatively, in Registry Editor, modify the “Enabled” DWORD value under 🗝️HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftBiometrics.
Turn On or Off Windows Hello Biometrics Using Local Group Policy Editor
The Local Group Policy Editor directly controls whether Windows Hello biometrics function for domain users.
Step 1Open Local Group Policy Editor
Press the Win and R together, type gpedit.msc, and press Enter.
Consult the “How to Open Local Group Policy Editor in Windows 11” guide for detailed steps on accessing this tool. Windows 11 Pro and Enterprise editions include this tool natively.
Step 2Find the Biometrics Settings
Navigate to the Biometrics category within the Local Group Policy Editor using this path: Computer Configuration Administrative Templates Windows Components Biometrics
Computer Configuration Administrative Templates Windows Components Biometrics
Step 3Change the Setting
The 'Allow domain users to log on using biometrics' setting governs Windows Hello domain users sign-in permissions on network accounts. Choose 'Enabled' or 'Not Configured' to permit users to sign in with their face or fingerprint, or select 'Disabled' to block biometric access entirely across the domain.

Select one of these options next:
- Not Configured – This means biometrics are allowed.
- Enabled – Biometrics will be allowed for domain users.
- Disabled – Biometrics will NOT be allowed for domain users.

Click OK to save the biometric setting changes. Restart your computer to apply the new policy.
Turn On or Off Windows Hello Biometrics Using Registry Editor
Windows Home editions lack the Local Group Policy Editor, requiring modifications through the Windows Registry instead.
Back up your registry before proceeding.
Step 1Open Registry Editor
The Registry Editor handles these changes if Group Policy isn't available. Press the Windows key and R together, type regedit, and press Enter to open it.
Consult "How to Open Registry Editor in Windows 11" for additional information. Advanced users modify system settings using the Registry Editor.
Step 2Navigate to the Biometrics Key
The Biometrics key must be located or created within the Registry Editor to manage Windows Hello domain users policies. Open Registry Editor and go to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft, then create a new key named Biometrics if it does not already exist in that folder.
Creating this folder ensures proper management of Windows Hello biometrics for domain users. The presence of the Biometrics folder is required for the subsequent configuration steps.
- Right-click on Microsoft → New → Key.
- Name the new key Biometrics.
Step 3Create or Edit the "Enabled" Value
The Enabled value within the Biometrics folder controls Windows Hello domain users settings through the registry. Set the value data to 1 to turn on face and fingerprint sign-ins, or set it to 0 to turn them off for network accounts.
Name this new value Enabled.
Double-click the Enabled value. Set the Base to Decimal. Then set the Value data to:
- 1 to turn ON biometrics for domain users.
- 0 to turn OFF biometrics for domain users.

Click OK and close the Registry Editor.
Restart your computer to apply these changes.
Summary
Windows Hello domain users settings let network administrators control face and fingerprint sign-in options. Work and school domains often turn off these features by default, but you can use the Registry Editor to turn them back on when needed.
Work or school domains often disable these sign-in options by default. Local Group Policy Editor or Registry Editor modifications allow enabling or disabling Windows Hello biometrics for domain users.
Remember to restart your computer after making any changes.
Consult these helpful guides to learn more about Windows Hello features:
How to Sign In with a PIN in Windows 11
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!