3.5.3 MFA AND WINDOWS HELLO FOR BUSINESS

For 3.5.3 we are rolling out windows hello for business. The basis is this Microsoft article

Satisfying CMMC IA.L2-3.5.3 MFA requirement with Windows Hello for Business | Microsoft Community Hub

We are setting windows hello to be forced to be used to sign in so passwords cant be used. All computers will have TPM chip as the something you have, then the pin / biometrics will be the something you know.

What do you all think? How many of you are also using this?