Allow enhanced PINs for startup

Information

This policy setting allows you to configure whether or not enhanced startup PINs are used with BitLocker.
Enhanced startup PINs permit the use of characters including uppercase and lowercase letters, symbols, numbers, and spaces. This policy setting is applied when you turn on BitLocker.
If you enable this policy setting, all new BitLocker startup PINs set will be enhanced PINs.
Note: Not all computers may support enhanced PINs in the pre-boot environment. It is strongly recommended that users perform a system check during BitLocker setup.
If you disable or do not configure this policy setting, enhanced PINs will not be used.

Solution

Policy Path: Windows Components\BitLocker Drive Encryption\Operating System Drives
Policy Setting Name: Allow enhanced PINs for startup

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-windows-10-and-windows-server-version/ba-p/1543631

Item Details

Category: IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|IA-5c., 800-53|SC-28(1), CSCv6|8.4, CSCv6|13.2, CSCv6|16.11

Plugin: Windows

Control ID: 9ab9e9c4636e0110a574ddb015969c73ec956cae7c7f3296cc0f5d0000b812f4