18.9.14.1 (L1) Ensure 'Require pin for pairing' is set to 'Enabled'

Information

This policy setting controls whether or not a PIN is required for pairing to a wireless display device.
The recommended state for this setting is: Enabled.
Rationale:
If this setting is not configured or disabled then a PIN would not be required when pairing wireless display devices to the system, increasing the risk of unauthorized use.

Solution

To establish the recommended configuration via GP, set the following UI path to Enabled:
Computer Configuration\Policies\Administrative Templates\Windows Components\Connect\Require pin for pairing
Note: This Group Policy path may not exist by default. It is provided by the Group Policy template WirelessDisplay.admx/adml that is included with the Microsoft Windows 10 Release 1607 & Server 2016 Administrative Templates (or newer).
Impact:
The pairing ceremony for connecting to new wireless display devices will always require a PIN.
Default Value:
Disabled. (A PIN is not required for pairing to a wireless display device.)
CIS Controls:
Version 6
15.8 Disable Wireless Peripheral Access (i.e. Bluetooth) Unless Required
Disable wireless peripheral access of devices (such as Bluetooth), unless such access is required for a documented business need.
Version 7
15.9 Disable Wireless Peripheral Access of Devices
Disable wireless peripheral access of devices (such as Bluetooth and NFC), unless such access is required for a business purpose.

See Also

https://workbench.cisecurity.org/files/2288