Why we need new hardware for face recognition? I understand the iris part, but from what I read there will be face recognition also. So why new hardware for that? My Nexus4 did that some years ago with a crappy cam.
If I remember reading somewhere, you need an infra red capable camera for the "Hello" feature to work, that way it can tell there's a real person in front.
You can let the people with old hardware chose to use face detection, that isn't very secure and people with new hardware secure face detection. If you do not want to understand that we can not help.
A normal camera isn't going to be able to determine a unique iris with suitable accuracy. Maybe there's some extra hardware bits too such as secure storage for encryption keys.
Do that and within days you'll have a ton of blogs and a million consumers screaming\laughing over how unprofessional and insecure the newest Windows security features are.
With your proposal, the majority of WP owners would be given a false sense of security. Providing no security at all would then actually be the better option. At least consumers would then realize that they are unprotected and adapt their behavior.
Considering a simple PIN is a lot more secure than a poorly implemented facial recognition system, there is no reason to go half way. The PIN is what those people without the necessary hardware should use.
By treating facial recognition as a serious feature, rather than a toy-feature on a marketing checklist (what you had on Android), MS is actually protecting your interests.