Configure enhanced anti-spoofing

Information

This policy setting determines whether enhanced anti-spoofing is required for Windows Hello face authentication.
If you enable this setting, Windows requires all users on managed devices to use enhanced anti-spoofing for Windows Hello face authentication. This disables Windows Hello face authentication on devices that do not support enhanced anti-spoofing.
If you disable or don't configure this setting, Windows doesn't require enhanced anti-spoofing for Windows Hello face authentication.
Note that enhanced anti-spoofing for Windows Hello face authentication is not required on unmanaged devices.

Solution

Policy Path: Windows Components\Biometrics\Facial Features
Policy Setting Name: Configure enhanced anti-spoofing

See Also

https://blogs.technet.microsoft.com/secguide/2019/05/23/security-baseline-final-for-windows-10-v1903-and-windows-server-v1903/

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6

Plugin: Windows

Control ID: a4cb1df11fa3d62892a3fb35b3c98bbd9e3037294ebd3f36bd159078d08584a8