3.10.25.7 (L1) Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled'

Information

This policy setting allows you to control whether a user can sign in using a convenience PIN.

Note: The user's password will be cached in the system vault when using this feature.

The recommended state for this setting is: Disabled

A PIN is created from a much smaller selection of characters than a password, so in most cases a PIN will be much less robust than a password.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled

Administrative Templates\System\Logon\Turn on convenience PIN sign-in

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: aa18b04802b96da101c8e8e70d7f30210d267575c1f2d2d239b6f7d9ab112db3