Hello! On questions 1, the answer is Yes. You can leave Login as Current User on but ignore the current user if the end point is using Hello for Business. Your end users using AD will continue to auto-auth and end users with WHFB will have to type in credentials to connect to Horizon. On question 2, the client GPO will work with older Horizon servers .