@Tom Wrigglesworth, Thanks for posting in Q&A. To deploy Windows Hello for Business through Intune, you need to configure a Windows Hello for Business policy and deploy it to the devices.
The Active Directory portion of the planning guide should be complete. Most of the conditions are baseline prerequisites except for your domain controllers. The domain controllers used in your deployment are decided by the chosen trust type.
Meanwhile please ensure that your devices meet the minimum client requirements.
Windows Hello for Business can use either key trust or certificate trust, depending on your deployment's trust type.
If you want to configure Windows Hello for Business settings with PIN, you can configure it via Identity protection policy or Settings catalog policy. Here is a link list the detailed settings for your reference:
https://video2.skills-academy.com/en-us/mem/intune/protect/identity-protection-windows-settings
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.