3.10.25.7 (L1) Ensure 'Turn on convenience PIN sign-in' is set to 'Disabled'

Information

This policy setting allows you to control whether a user can sign in using a convenience PIN.

Note: The user's password will be cached in the system vault when using this feature.

The recommended state for this setting is: Disabled

A PIN is created from a much smaller selection of characters than a password, so in most cases a PIN will be much less robust than a password.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled

Administrative Templates\System\Logon\Turn on convenience PIN sign-in

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/16852

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7

Plugin: Windows

Control ID: 968e9d603443722eb89df2cfc981ff35154cf84befac3843bf7255aa984c272b