How to Enable or Disable Windows Hello Biometrics for Domain Users
Windows Hello biometrics management for domain users is controlled through Group Policy settings in Windows 11. Domain users are those connected to a network, like at work or school.
Windows Hello lets you sign in easily and securely using your face, fingerprint, or a PIN. Many newer PCs come with this feature ready to go.
IT administrators can use central policies to prevent fingerprint and facial recognition for computers on a network. These rules can stop you from turning on Windows Hello biometrics, even though it boosts security.
This guide explains how to manage Windows Hello biometrics for accounts on Windows 11 computers joined to a domain.
Configure Windows Hello biometrics for domain users via Group Policy Editor or Registry Editor. Navigate to Administrative Templates > Windows Components > Biometrics in Group Policy, then adjust the “Allow domain users to log on using biometrics” setting. Alternatively, in Registry Editor, modify the “Enabled” DWORD value under 🗝️HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftBiometrics.
Turn On or Off Windows Hello Biometrics Using Local Group Policy Editor
The Local Group Policy Editor, a Windows tool, directly controls advanced settings. This tool manages whether Windows Hello biometrics function for domain users.
Step 1Open Local Group Policy Editor
Opening the Local Group Policy Editor allows for managing specific Windows settings, including control over Windows Hello biometrics for domain users. Press the Windows key and R together, type gpedit.msc, and press Enter to open it.
For detailed steps on opening the Local Group Policy Editor, consult the “How to Open Local Group Policy Editor in Windows 11” guide. This tool is included in Windows 11 Pro and Enterprise editions.
Step 2Find the Biometrics Settings
To manage Windows Hello biometrics for domain users, find the Biometrics settings in the Local Group Policy Editor by following this path: Computer Configuration → Administrative Templates → Windows Components → Biometrics.
Computer Configuration → Administrative Templates → Windows Components → Biometrics
Step 3Change the Setting
You can control Windows Hello biometrics for domain users by changing the ‘Allow domain users to log on using biometrics’ setting. Choose ‘Enabled’ or ‘Not Configured’ to permit domain users to sign in with their face or fingerprint.

Now select one of these options:
- Not Configured – This means biometrics are allowed.
- Enabled – Biometrics will be allowed for domain users.
- Disabled – Biometrics will NOT be allowed for domain users.

Clicking OK saves the biometric setting changes. Restarting the computer applies these biometric changes for domain users, ensuring Windows Hello fingerprint and facial recognition settings are active or inactive as intended.
Turn On or Off Windows Hello Biometrics Using Registry Editor
If you can’t use the Local Group Policy Editor (for example, on Windows Home editions), you can change the setting by editing the Windows Registry.
Step 1Open Registry Editor
Opening the Registry Editor lets you make advanced changes to Windows settings, including managing Windows Hello biometrics for domain users. Press the Windows key and R together, type regedit, and press Enter to open it.
This guide, “How to Open Registry Editor in Windows 11,” provides additional information. The Registry Editor in Windows 11 lets advanced users modify system settings by editing the Windows Registry, which is a database holding low-level configurations for the operating system and its applications.
Step 2Navigate to the Biometrics Key
You need to find the Biometrics key in the Registry Editor to manage Windows Hello biometrics for domain users. Go to 🗝️HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft. If the Biometrics folder isn’t there, create it by right-clicking Microsoft, selecting New, then Key, and naming it Biometrics.
- Right-click on Microsoft → New → Key.
- Name the new key Biometrics.
Step 3Create or Edit the “Enabled” Value
To control Windows Hello biometrics for domain users using the registry, create or edit the ‘Enabled’ value within the Biometrics folder. Set the Base to Decimal and the Value data to 1 to enable biometrics, or to 0 to disable them.
Name this new value Enabled.
Double-click the Enabled value. Set the Base to Decimal. Then set the Value data to:
- 1 to turn ON biometrics for domain users.
- 0 to turn OFF biometrics for domain users.

Press OK and close the Registry Editor.
Restart your computer to apply these changes.
Summary
Windows Hello biometrics offers secure sign-in options like face or fingerprint scanning. Administrators control Windows Hello settings for domain users. If your PC is part of a work or school domain, these Windows Hello features may be turned off by default, but you can turn them on or off.
If your PC belongs to a domain (such as for work or school), these sign-in options may be disabled by default. You have the option to enable or disable Windows Hello biometrics for domain users using either the Local Group Policy Editor or the Registry Editor.
Remember to restart your computer after making any changes.
If you want to learn more about Windows Hello features, here are some helpful guides:
How to Sign In with a PIN in Windows 11
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!