1) [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]
        "AllowDomainPINLogon"=dword:00000001


2)    All 3 Policies under Computer Configuration\Administrative Templates\Windows Components\Windows Hello for Business\ must be in the state "Not configured".