Refactor code to improve performance and readability

This commit is contained in:
Paolo Matarazzo 2024-01-22 12:50:35 -05:00
parent 3d18fefe2d
commit c56127fbfa

View File

@ -102,12 +102,12 @@ Windows Hello for Business is enabled by default for devices that are Microsoft
- Provision the devices using a provisioning package that disables Windows Hello for Business. For more information, see [Provisioning packages for Windows](/windows/configuration/provisioning-packages/provisioning-packages)
- Scripted solutions that can modify the registry settings to disable Windows Hello for Business during OS deployment
| Policy type | Registry path | Value |
|-|-|-|
| CSP (user)| `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\UserSid\Policies`| `UsePassportForWork` <br> - DWORD `0` to Disable<br>- DWORD `1` to Enable|
| CSP (device)| `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies`| `UsePassportForWork` <br> - DWORD `0` to Disable<br>- DWORD `1` to Enable|
| GPO (user)| `HKEY_USERS\<UserSID>\SOFTWARE\Policies\Microsoft\PassportForWork`| `Enabled` <br> - DWORD `0` to Disable<br>- DWORD `1` to Enable|
| GPO (device)| `HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork`| `Enabled` <br> - DWORD `0` to Disable<br>- DWORD `1` to Enable|
| Setting |
|--|
| CSP (user)<br>**Key path**: `HHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\UserSid\Policies` <br>**Key name**: `UsePassportForWork`<br>**Type**: `REG_DWORD`<br>**Value**:<br>&emsp;`1` to enable<br>&emsp;`0` to Disable |
| CSP (device)<br>**Key path**: `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies` <br>**Key name**: `UsePassportForWork`<br>**Type**: `REG_DWORD`<br>**Value**:<br>&emsp;`1` to enable<br>&emsp;`0` to Disable |
| GPO (user)<br>**Key path**: `HKEY_USERS\<UserSID>\SOFTWARE\Policies\Microsoft\PassportForWork` <br>**Key name**: `Enabled`<br>**Type**: `REG_DWORD`<br>**Value**:<br>&emsp;`1` to enable<br>&emsp;`0` to Disable |
| GPO (user)<br>**Key path**: `KEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PassportForWork` <br>**Key name**: `Enabled`<br>**Type**: `REG_DWORD`<br>**Value**:<br>&emsp;`1` to enable<br>&emsp;`0` to Disable |
> [!NOTE]
> If there's a conflicting device policy and user policy, the user policy takes precedence. It's not recommended to create Local GPO or registry settings that could conflict with an MDM policy. This conflict could lead to unexpected results.