18.10.13.1 Ensure 'Require pin for pairing' is set to 'Enabled'

Information

This policy setting controls whether or not a PIN is required for pairing to a wireless display device.

The recommended state for this setting is: Enabled.

Rationale:

If this setting is not configured or disabled then a PIN would not be required when pairing wireless display devices to the system, increasing the risk of unauthorized use.

Impact:

The pairing ceremony for connecting to new wireless display devices will always require a PIN.

Solution

To establish the recommended configuration, set the following Device Configuration Policy to Require:

To access the Device Configuration Policy from the Intune Home page:

Click Devices

Click Configuration profiles

Click Create profile

Select the platform (Windows 10 and later)

Select the profile (Device restrictions)

Click Create

Enter a Name

Click Next

Configure the following Setting

Path: Device restrictions/Projection
Setting Name: Require PIN for pairing
Configuration: Require

Select OK

Continue through the Wizard to complete the creation of the profile (profile assignments, applicability etc.)

Note: More than one configuration setting from each of the Configuration profiles (ex: Administrative Templates, Custom etc.) can be added to each Device Configuration Policy.

Note #2: This setting can also be created via a Custom Configuration Profile using the following OMA-URI:

Name: <Enter name>
Description: <Enter Description>
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/WirelessDisplay/RequirePinForPairing

Default Value:

Disabled. (A PIN is not required for pairing to a wireless display device.)

See Also

https://workbench.cisecurity.org/benchmarks/14664

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5c.

Plugin: Windows

Control ID: c0c9746e6504eec1d3a2c91089a174faa1eff4aeaf9e71d3c214e95f4ca9766e