98.1 Ensure 'Enable ESS with Supported Peripherals' is set to 'Enhanced sign-in security will be enabled...'

Information

Enhanced Sign-in Security isolates Windows Hello biometric (face and fingerprint) template data and matching operations to trusted hardware or specified memory regions.

The recommended state for this setting is: ESS will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. Authentication operations of any peripheral biometric device will be blocked and not available for Windows Hello. (default and recommended for highest security)..

Because the channel of communication between the sensors and the algorithm is secured, it is impossible for malware to inject or replay data in order to simulate a user signing in or to lock a user out of their machine.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Enhanced sign-in security will be enabled... :

Windows Hello For Business\Enable ESS with Supported Peripherals

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/27282

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-16, CSCv7|8.3

Plugin: Windows

Control ID: 6b907af61b09dd580d18d024e4a04cfe2ea8158f265cfd51d489d723be49737b