Configure minimum PIN length for startup

Information

This policy setting allows you to configure a minimum length for a Trusted Platform Module (TPM) startup PIN. This policy setting is applied when you turn on BitLocker. The startup PIN must have a minimum length of 4 digits and can have a maximum length of 20 digits.

If you enable this policy setting, you can require a minimum number of digits to be used when setting the startup PIN.If you disable or do not configure this policy setting, users can configure a startup PIN of any length between 4 and 20 digits.

Solution

Policy Path: Windows Components\BitLocker Drive Encryption\Operating System Drives
Policy Setting Name: Configure minimum PIN length for startup

See Also

https://blogs.technet.microsoft.com/secguide/2015/11/13/security-baseline-for-windows-10-build-10240-final/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SC-28(1), 800-53|SI-7(9), CSCv6|2, CSCv6|13.2

Plugin: Windows

Control ID: ee1f1ebda105f9e95a2966c87f2fff1f70cbaa1c68a13d692f3e48cbd1ff5718