79.2 (L1) Ensure 'Minimum PIN Length' is set to '6 more character(s)'

Information

Minimum PIN length configures the minimum number of characters required for the PIN. The lowest number you can configure for this policy setting is 4. The largest number you can configure must be less than the number configured in the Maximum PIN length policy setting or the number 127, whichever is the lowest.

The recommended state for this setting is: 6 more character(s)

Windows Hello for Business utilizes key-based or certificate-based authentication and makes credential theft extremely difficult.

When backed with a TPM chip multiple physical security mechanisms are added in order to make it tamper resistant.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to 6 (or more character(s)):

Windows Hello For Business\Minimum PIN Length

Impact:

PIN theft is possible through shoulder surfing or other means of reconnaissance. Although this threat applies to passwords as well it is reduced with passphrases which involve complexity and length.

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|4.4, CSCv7|16.2

Plugin: Windows

Control ID: 7ffb926fbf1c77985d0bc1163fe26395b52d1b287ada351f7fc0bd0257918a98