Hexnode currently does not have a native Windows policy setting to explicitly disable or gray out the PIN (Windows Hello) option on managed Windows devices.
If the requirement is specifically to prevent users from configuring Windows Hello PIN locally, this is not available as a built-in Hexnode restriction at the moment.
As an alternative, you can deploy a custom PowerShell script using the Execute Custom Script action if your organization has a tested script for your Windows environment. However, the script logic must be validated internally, as behavior can vary depending on Windows edition, domain/Azure AD state, Windows Hello for Business configuration, and existing local policies.
If your goal is to manage local account credentials rather than PIN sign-in, Hexnode can update local account passwords from the device page:
1. Go to Manage.
2. Open the Windows device.
3. Navigate to the Local Accounts sub-tab.
4. Use the actions menu next to the account.
5. Select Change Password.
This changes the local account password, but it does not disable or gray out the Windows Hello PIN option.
Regards,
Mary Romero