First, the problem phenomenon
After the Windows 10 client update August 3, 2016 anniversary update, the version is updated to 1607, after joining the domain (AD version for Windows Server R2) Windows Hello is set to gray and cannot be set, prompting "some settings are managed by your organization".
650) this.width=650; "height=" 275 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M01/86/A7/ Wkiom1fgl-drcddfaahjzyt9da8363.png "border=" 0 "/>
Second, the cause of the problem
Because there is no setting for pin sign-in in Windows Server R2 Group Policy, Windows 10 R2 disables pin logon by default after upgrading to version 1607. If you want to enable the Windows Hello feature, you only need to turn on the Turn on convenience pin sign-in through Group Policy, and the key setting Turn on convenience pin sign-in cannot be found in the default system settings. You can only download the latest Windows 10/server 2016 Administrative Templates to find.
As found in the description of the Windows 10 Group Policy template provided by Microsoft, enabling the turn on convenience PIN sign-in only requires copying the credentialproviders.admx template.
650) this.width=650; "height=" "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M01/86/A7/ Wkiol1fgmk6zmgataag3npgpcek350.png "border=" 0 "/>
Third, the solution
There are two scenarios for solving this approach:
In either case, the first step is to download the Windows 10 Group Policy template file (currently this template does not have a Chinese language environment, I joined the domain of Windows 10 is the Chinese version, using Group Policy English template is also available),: https://www.microsoft.com/ en-us/download/details.aspx?id=53430 (i downloaded it in English)
Situation One:
1), Group Policy template is not enabled to retrieve policy from central store (that is, use Group Policy template to keep domain control locally without replicating to other domain controls)
A. Extract the downloaded ADMX files (MSI format) to the local disk.
650) this.width=650; "height=" 233 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M02/86/A8/ Wkiom1fgmk7tir3raabm9dnmknw498.png "border=" 0 "/>
B, the extracted file "C:\Program files (x86) \microsoft Group Policy\windows and Windows Server 2016\policydefinitions\ CREDENTIALPROVIDERS.ADMX"Copy to AD domain controlled directory: C:\Windows\PolicyDefinitions
650) this.width=650; "height=" 319 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M02/86/A7/wKioL1fGmK_ Dalhkaafjdlhb9do538.png "border=" 0 "/>
C, the template language file "C:\Program files (x86) \microsoft Group Policy\windows and Windows Server 2016\policydefinitions\en-us\ Credentialproviders.adml"copied to the domain control directory: C:\Windows\PolicyDefinitions\zh-CN and C:\Windows\PolicyDefinitions\en-US.
650) this.width=650; "height=" title= "image" style= "Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M00/86/A7/ Wkiol1fgmlchbv4paaexs-wg-ni699.png "border=" 0 "/>
D, set Group Policy to turn on the turn on convenience PIN sign-in. After the Group Policy setting is complete, use the command: Gpupdate/force to force the following Group Policy to refresh.
650) this.width=650; "height=" 339 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M01/86/A8/ Wkiom1fgmlobl-z6aahgnmh18j8308.png "border=" 0 "/>
Situation Two:
2), Group Policy templates enable retrieval of policies from central storage.
A. Extract the downloaded ADMX files (MSI format) to the local disk.
650) this.width=650; "height=" 233 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M01/86/A8/wKiom1fGmLOSgdO4AABQ5b_ Lwke034.png "border=" 0 "/>
B, the extracted file "C:\Program files (x86) \microsoft Group Policy\windows and Windows Server 2016\policydefinitions\ CREDENTIALPROVIDERS.ADMX"Copy to AD domain controlled directory: C:\Windows\SYSVOL\sysvol\contoso.com\Policies\PolicyDefinitions
650) this.width=650; "height=" 347 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M01/86/A7/ Wkiol1fgmlsykhpeaagytgvqvnw046.png "border=" 0 "/>
C, the template language file "C:\Program files (x86) \microsoft Group Policy\windows and Windows Server 2016\policydefinitions\en-us\ Credentialproviders.adml"Copy to Domain control directory: C:\Windows\SYSVOL\sysvol\contoso.com\Policies\PolicyDefinitions\en-US and C : Under \WINDOWS\SYSVOL\SYSVOL\CONTOSO.COM\POLICIES\POLICYDEFINITIONS\ZH-CN.
650) this.width=650; "height=" title= "image" style= "Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M01/86/A7/wKioL1fGmLXCpFu4AACfqSX_ 484257.png "border=" 0 "/>
650) this.width=650; "height=" 351 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M02/86/A8/wKiom1fGmLbD7tiBAAG_ Scjiyw8362.png "border=" 0 "/>
D, set Group Policy to turn on the turn on convenience PIN sign-in. After the Group Policy setting is complete, use the command: Gpupdate/force to force the following Group Policy to refresh.
650) this.width=650; "height=" 339 "title=" image "style=" Border:0px;padding-top:0px;padding-right:0px;padding-left : 0px;background-image:none; "alt=" image "src=" http://s3.51cto.com/wyfs02/M02/86/A7/ Wkiol1fgmljiblmtaahgnmh18j8876.png "border=" 0 "/>
This article is from the "Jialt blog" blog, make sure to keep this source http://jialt.blog.51cto.com/4660749/1844828
Windows Hello Workaround is not available after you join a domain after you have a 10 1607 (anniversary update)