Configure minimum PIN length for startup

Information

This policy setting allows you to configure a minimum length for a Trusted Platform Module (TPM) startup PIN. This policy setting is applied when you turn on BitLocker. The startup PIN must have a minimum length of 4 digits and can have a maximum length of 20 digits.

If you enable this policy setting you can require a minimum number of digits to be used when setting the startup PIN.

If you disable or do not configure this policy setting users can configure a startup PIN of any length between 6 and 20 digits.

NOTE: If minimum PIN length is set below 6 digits Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful Windows will only reset the TPM lockout period back to default if the TPM is reset.

Solution

Policy Path: Windows Components\BitLocker Drive Encryption\Operating System Drives
Policy Setting Name: Configure minimum PIN length for startup

See Also

https://blogs.technet.microsoft.com/secguide/2018/04/30/security-baseline-for-windows-10-april-2018-update-v1803-final/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SC-28(1), 800-53|SI-7(9), CSCv6|2, CSCv6|13.2

Plugin: Windows

Control ID: 86dd4751742e12c2f0274af563916b00e4a2da15637c7e9c5ea74eff88f731c8