24.1 (L1) Ensure 'Alphanumeric Device Password Required' is set to 'Password, Numeric PIN, or Alphanumeric PIN required'

Information

This policy setting determines the type of PIN or password required. This policy only applies if the DeviceLock/DevicePasswordEnabled policy is set to 0. In settings catalog this setting is a pre-requisite for 'Min Device Password Complex Characters'.

The recommended state for this setting is: Password, Numeric PIN, or Alphanumeric PIN required

This is a pre-requisite for 'Min Device Password Complex Characters', which enforces a more complex local user account password. This has no impact on Entra ID accounts.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Password, Numeric PIN, or Alphanumeric PIN required :

Device Lock\Device Password Enabled: Alphanumeric Device Password Required

Impact:

If an organization is using Windows Hello for Business the the Device Lock password settings can impact PIN polices if those policies are not first defined elsewhere. Windows will follow the Windows Hello for Business policies for PINs if this key exists: HKLM\SOFTWARE\Microsoft\Policies\PassportForWork\<Tenant-ID>\Device\Policies Otherwise, it will follow Device Lock policies.

This benchmark recommends configuring Device Lock policies for Local User accounts and Windows Hello for Business policies for PINs.

See Also

https://workbench.cisecurity.org/benchmarks/16853

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1), CSCv7|16.2

Plugin: Windows

Control ID: daa8ab562fac2a2f0b59bd7444d68ff4e5fbfc40fff9b93008ed06f0946a5707