There are multiple options available for implementing Windows Hello for Business. The best choice for you will depend on a number of variables, including your operating system version, whether you handle certificates on user devices, and if you have an on-prem, cloud-only, or hybrid environment.
It is easier and efficient to deploy but doesn’t support Remote Desktop Connections. You’ll need a minimal PKI/AD Certificate Services (AD CS) service to deploy updated certificates to your DCs.
It is more secure and trusted and needs a public key infrastructure (PKI) for certificate deployment. It might fit right in if your business already has that deployed.