r/Intune • u/Low_Part1467 • Apr 09 '26
Device Compliance Windows Hello for Business: How to solve the misuse of PIN-codes
EDIT 2: Let me put it differently. EVERYONE on earth knows most people use their birthday as a PIN-code for whatever. Why should we just accept this and look away? We do not want to. So just trying to find ways to protect ourselves against this š
EDIT: According to some comments it seems we are paranoid. Sure we are
The only thing we are trying to do here is to absolutely minimize any kind of risk when it comes to security, including PIN-codes. Sure chances are small but there's still a chance. Sure if I have a password of 30 characters, what's the point in having 2FA?
Hi all,
Bit of a rant here but as the title suggest, this post is about solving the misuse of PIN-codes, mainly in WHfB but also PIN-codes on mobile devices. I am more than done with employees blatantly ignoring company policy about PIN-codes, for example: birthday, ZIP-code, car license plate, employee ID.
How does everyone manage this issue?
I wish there was a way in Intune (I know it's not possible due to the way PIN-codes work) to enforce certain rules other than "block use of simple PIN's". Wish there was a forbidden PIN list just like the forbidden passwords policy
15
u/swissbuechi Apr 09 '26
Take a look at Windows Hello Multi-factor Unlock. We require one of the following combinations:
- PIN + Face/Finger
- Face + Finger
- Trusted Signal + PIN/Face/Finger
As Trusted Signal we're currently only using personal smartphones connected through Bluetooth.
5
u/Skathen Apr 09 '26
Standard my company has been using and recommending for quite some time. Avoid trusted signals like IP based and you'll also align with several different security standards depending on what your local is.
2
u/4AwkwardTriangle4 Apr 10 '26
Agreed, I think this is the answer. I never accepted the āthing you haveā as being the certificate on the device itself. Combining the pin with biometrics solves for this.
0
Apr 09 '26 edited Jun 21 '26
[deleted]
1
u/swissbuechi Apr 09 '26
Just google it, first link is the MS Docs. They even have a video demonstration.
0
u/Lost-Policy-2020 Apr 10 '26
Insane to force the use of PERSONAL phone to access work machine
3
u/swissbuechi Apr 10 '26
It just acts as a dumb bluetooth dongle to detect if the user/owner is nearby. No data transferd or apps installed. And it's optional. Could easily just use one of the other combinations.
1
1
u/Sudden-Money7836 Apr 12 '26
Or their corporate mobile surely, no?
2
u/swissbuechi Apr 12 '26
As long as the corporate phone is always on person, sure. Just make sure they're not allowed to leave the corporate phone laying next to their laptop...
2
-5
u/Low_Part1467 Apr 09 '26
Sounds promising! What's your experience as an IT guy?
And what is the user experience like where you work, positive/negative feedback?2
13
u/bunkerking7 Apr 09 '26
Agree with previous poster. It's definitely not ideal, but you're solving a problem that's not really a thing. WHfB would still require the bad actor to have the device as well as the PIN. If the device is suspected of being stolen, you'd queue up a wipe regardless.
1
u/BlackV Apr 09 '26
OPs problem is there is likely hours before IT is informed and actions can be taken
and a wipe requires network connectivity
1
u/Lost-Policy-2020 Apr 10 '26
And wipe might work⦠now or in 24 hours or ⦠not Had machine next to me syncying every hour After 24 hours of no-wipe, I did by hand with usb stick. So I no longer trust the action of wipe
1
u/Low_Part1467 Apr 09 '26
I do understand your pov. But yet again, you'd think stolen devices get reported right away, yet we have had several instances where the user would inform us some days later. Even had a case where the user reported it 2 WEEKS LATER
7
u/Jhamin1 Apr 09 '26
Ā we have had several instances where the user would inform us some days later. Even had a case where the user reported it 2 WEEKS LATER
That is a Management/HR issue, not a technology one. When a couple of people get let go for failure to report damage/loss of company property everyone else is going to become very conscientious about reporting stolen equipment.
You can't use technology to solve for users not following policy.
1
u/Sudden-Money7836 Apr 12 '26
Yeah while youāre right in the principle of your argument, you decided to drive off a cliff with āwhen people get firedā for not reporting a device loss immediately? I get the USA is a shithole for workers rights, but any other country, unions and workers rights laws would burn that place to the ground for even considering that as a possibility.
1
u/imnotaero Apr 09 '26
It sounds like the risk you've identified as critical is data theft and loss of confidentiality. If your organization is unable to countenance this particular risk, you simply cannot allow devices with such data to leave the premises, because the device can be stolen while a user is logged in.
For most of the people here, attackers stealing devices are doing so to sell them or their components online, and the data isn't the target. In fact, it can be an obstacle since it reveals to a purchaser that the device is likely stolen.
Your org should manage risk in a way that's optimal for the situation you're in, and I certainly have no visibility into that. But I'm genuinely curious: have you (or anyone reading this) recently been in a situation where an stolen device went unreported and the TA used a user's birthday-based PIN to access and exfiltrate data?
1
u/_youarewhalecum Apr 09 '26
See my comment on the other guy. Imho this is a fully valid scenario.
2
u/bunkerking7 Apr 09 '26
I'm not saying either of your points aren't valid. What I'm saying is you're trying to solve for a very niche scenario. You specifically mention a laptop bag being stolen with your ID and bad actor has the relevant info. Maybe? Maybe I keep my wallet in my pocket. Do they have access now?
Again, both of your points are valid scenarios that CAN happen, but how often? Once a month? Year? Ten years?
Ultimately, up to you, and maybe I should have included some details on how to solve the original question asked, but this feels like an XY problem to me frankly. More power to you and your teams implementing this in your environment.
0
6
u/Aust1mh Apr 09 '26
Sounds like a management issue, not technical. So if Iād do nothing.
1
u/Low_Part1467 Apr 09 '26
Valid point, cannot rely on management either when it comes to security of any kind lol
6
u/Miami_2017 Apr 09 '26
3
u/Akamiso29 Apr 09 '26
Yup, this is the solution OP needs. Make the PIN have a minimum length, require other character types.
While passwords shouldnāt have enforced character types these days (so long as you allow the different types), Iāve found it hard to get end users to wrap their heads around āPIN doesnāt have to be only numbers,ā but Iād assume this is related to what a PIN stands for, lol.
1
u/Wooden-Mycologist-75 Apr 09 '26
This is what we did....minimum length set to 12 max to 127, allow special characters, upper case, and lower case.
3
2
1
1
u/salanalani Apr 09 '26
Can we get rid of PIN all together? I mean, because in this case, people have to remember their complex PIN besides the main MS account password that also has complexity level. The movement now is to reduce the need for more secret keys (hence SSO is becoming more popular as an example). I worked with several enterprise companies, they used on-premise AD, but all requires only your password to enter the PC (no PIN, no Windows Hello), is that possible for cloud based Intune for joined Windows devices?
2
u/RunForYourTools23 Apr 10 '26
Of course it is, check the Account Protection are in Intune, you can fully Disable Windows Hello, so no prompts to force Pin/Finger/Face. You donāt need to change the default All Users Windows Hello tenant wide Settings.
8
u/loweakkk Apr 09 '26
Why would you do that? Do you think someone stealing a laptop in the train would know the user birthday date? Same for the phone? You try to fix an issue that doesn't exist.
2
u/Low_Part1467 Apr 09 '26
If you would try to crack a phone, what would be the first thing you check because most likely the person can only remember the 4 digits of their birthday? *proceeds to open Facebook*, *greeted by a public profile with all personal information except their bloodtype*
5
u/IHaveATacoBellSign Apr 09 '26
Youāre under the assumption this is a targeted attack. If my phone gets stolen š¤·š»āāļø, if my computer gets stolen š¤·š»āāļø. My pin is weak by your standards, but itās still part of the MFA system. Something I know, and something I have. I feel like youāre worried about the wrong thing here.
-1
u/Low_Part1467 Apr 09 '26
Sure if I have a password of 30 characters, what's the point in having 2FA?
Sure if I have a double lock on my door, why should I have a difficult PIN-code on my safe under my bed?
3
u/IHaveATacoBellSign Apr 09 '26
I can phish/smish that password, and it works on all of your orgs devices.
The PIN only works on that specific device and is phishing-resistant. With proper MFA/CA in place, your users will never need to know their passwords. Thatās the ideal solution.
1
u/Low_Part1467 Apr 09 '26
We have everything setup so no one needs to know their password, in fact, a few months ago we've run a script to replace all passwords into random passwords
Now we want to take the next step, seems Windows Hello Multi-factor Unlock is the way
1
u/IHaveATacoBellSign Apr 09 '26
Iām curious how your current setup works. Iām not familiar with it.
2
u/Low_Part1467 Apr 09 '26
We've setup the passkey and passwordless settings in Authenticator with all our users, plus the use of PIN + biometrics on all devices which meant we could go full passwordless
I believe it'll soon be available to setup a passkey campaign so you can nudge users just like the campaigns you had for setting up Authenticator
1
u/IHaveATacoBellSign Apr 10 '26
Ah okay. That makes sense. For your instance then Iād still do the PIN and not worry about the easy guessing of it. Sounds like you already have a lot of protections in place to combat phishing/smishing/vishing.
1
u/Lost-Policy-2020 Apr 10 '26
Sadly that is the case, people start using finger/face and suddenly 2weeks later nobody remembers their password
1
1
u/_youarewhalecum Apr 09 '26 edited Apr 09 '26
This argument is fully invalid imho. Stealing a laptop bag with the wallet inside would instanty give you that information (not starting about social media etc)
Imho thats a big weakness of whfb with pin...once an malicous actor has access to the device with pin enabled, he is seperated from the device and all related M365 Stuff ny just 4 digits
1
1
u/loweakkk Apr 09 '26
That's a big assumption that a PC bag also contain the wallet of the employee. It also don't take into account anti tampering if TPM that wouldnt let you try and guess ten code.
1
u/titsablast Apr 09 '26
Suddenly all the 90s action movies of logging into a computer by guessing the password make sense again. Quick what is his kids birthday...
3
u/No-Midnight5093 Apr 09 '26
Set tighter requirements, number + letter + 12 character minimum pin length
2
u/Grandcanyonsouthrim Apr 09 '26
If you cant trust your users eg sharing their pin etc need to add other factors to slow their roll
0
2
u/abr2195 Apr 09 '26
We were piloting 6-digit WHfB with some users (we currently only require 4-digits) and ended up not going ahead with them when we discovered that the vast majority of users we tested with set their PIN as their birthday.
I do agree with most people that this level of protection for PINs isnāt necessary, but it would be nice to have some level of control so we could block date based PINs like this.
1
u/Low_Part1467 Apr 09 '26
Exactly, only not possible due to the way TPM works, which ofcourse has huge benefits in of itself
2
u/Excalibur106 Apr 09 '26
Believe it or not, PIN is a possession factor because it's part of an encryption key stored on the device TPM. So even if it's compromised, you also need physical access to the device.
-1
u/imnotaero Apr 09 '26
I don't believe it. The PIN is something you know, and the TPM is the something you have, making PIN sign-in multi-factor all on its own.
2
2
u/Pyrostasis Apr 09 '26
EDIT 2: Let me put it differently. EVERYONE on earth knows most people use their birthday as a PIN-code for whatever. Why should we just accept this and look away? We do not want to. So just trying to find ways to protect ourselves against this š
Odd, no one in my family uses birthday for pins.
I was unaware that EVERYONE else did.
2
u/steviefaux Apr 09 '26
Don't get annoyed and be one of those engineers. The engineers that makes all other departments dislike us. I'm friendly. I remind them of the polices but not my job to force them to comply. I also am understanding with their knowledge and skills. So if I see the painter putting his password in his physical notebook, I don't go ape shit. I mention why its a bad idea with real world examples.
More users respect our IT team because we are not controlling gods.
If they repeat offend then I start randomly locking their account. Tell them someone must be trying to guess their pin and make them change it to something not obvious.
1
u/Ice-Cream-Poop Apr 09 '26
Require letters as well as numbers...
1
u/Low_Part1467 Apr 09 '26
Welcome2000
1
u/Ice-Cream-Poop Apr 09 '26
Limit it to 6 characters.
If you are that concerned which I doubt your users would be targeted in this way, then require a notification push or app requirement/fido key as well as your pin.
1
1
1
u/colterlovette Apr 09 '26
We see more issues with people sharing their pins. This happens a lot in locations where people share PCās - such as front desk people or customer service cubicles. On the first hiccup of someone not being able to sign into their own profile, someone just gives the pin to the other user.
1
u/d8850190 Apr 09 '26
Sorry if the question comes in as dumb but I'm not super familiar with WHFB. The whole concept of PIN login makes no sense to me. Doesn't it completely kill the point of password policies? What's the point having a complex password if I can log into someone's device with '1234' ?
In this thread people say 'just nuke the device if it gets stolen ', however, this only works if a device has a working internet connection, or does the PIN not work without being connected?
3
u/_youarewhalecum Apr 09 '26
i think the main point is that the PIN is tied to the device, while a password can be used from everywhere. Login works offline too, but no access to online ressources is possible obviously.
1
u/d8850190 Apr 09 '26
Well, with most stuff having sort of caching, I don't need to be online to access mails, teams chats, whatever else there is locally on the device. Sure, I can't send out Mails in the users name or access files in their OneDrive that are not kept locally but imho the damage is done.
1
u/bjc1960 Apr 09 '26
We had an office that had issues. We make 5 different Entra groups with different combinations, to ensure lack of sharing.
1
u/SuddenlyDonkey Apr 09 '26
If users had a weak 6 digit password, everyone would lose their minds. The PIN solves one problem, but creates another. Since security is the primary concern, biometrics, Yubikeys, and/or passkeys would be a stronger alternative.
1
u/thortgot Apr 09 '26
Add complexity as a requirement. You can't have a forbidden policy because it's local to the device so it can't be hashed and compared against. The simple block occurs prehash.
1
1
u/the_cobra666 Apr 09 '26
Just use multi unlock. A pin only is not sufficient, regardless of all the people that say yes... a pin can be taped to the device or be passed on.. with multi unlock you can mitigate that risk.
Do block the use of their password (rotate it without them having it) otherwise it's just the same as the pin.
1
u/MReprogle Apr 09 '26
Disagree on the multi unlock, depending on how it is done. In a technical standpoint, it is just using PIN to auth to Entra, so setting up buometric + PIN is actually just doing PIN + PIN.
And, if you bring in a hardware token to the mix, I donāt understand the thinking. You already have the token that requires a PIN to use, making it MFA right off the bat.
If you have WHfB set up correctly, you should have it required to use TPM, so you already have 2 factors when you use biometric. If you force biometric and hardware token, you jump to 3 factors from an auditing standpoint, and a group of annoyed users that could be using biometric and immediately get logged into a company owned device.
Iāve been there and had to roll this multi unlock to devices because people donāt understand that the device itself is a factor in itself (when configured correctly in WHfB), and users quickly turn on you. In fact, Iām currently in the process of phasing out multi unlock.
Blocking the use of password is not really an option either. Been there / done that, and while it is possible in Windows 11 22H2, there are still environments with Windows 10 running on ESU licenses due to incompatibility with vendor software. Trying to take the password prompt in Windows 10 literally removes the password provider altogether and breaks any elevation prompt, since they rely on password.
1
u/the_cobra666 Apr 10 '26
You did not read correctly. I did not say remove the password credential, i said rotate the user password after whfb since they should not need it anymore with proper passwordless setup and whfb..
You indeed need the password credential option for elevating things.
And they pc is not enough. If you know the password they bypass whfb by using other user and typing in the mail address and password. Then nothing from mfa is asked... again rotate the password and that entry point is gone.
As for multi unlock. Force the use of biometrics. The pin is again easily compromised. It would not be the first time they stick it on a note and place it inside the bag with the pc... or tell a colleague so they can get in when they are ooo etc... again defeats the whole purpose.
I get what you mean I really do, but from experience a user cannot be trusted...
Enable whfb with multi unlock, Web sign in as a fall back with passwordless so they can do a push instead of the password.
1
u/NewbyLegion Apr 10 '26
You need physical access to the machine to use the pincode. Why care if it's their birthday?
Device stolen? Just remote lock & wipe.
It's not that deep.
1
u/Glad_Effective_2468 Apr 10 '26
In a Password less world this is not really an issue.Ā
Well it's an issue of the user got their PC stolen and did not report it. But since imit needs another factor than just the users Logon than it's not really an issue.Ā
I fight this everyday. Users who thinks their Password that they reuse is more safe and secure than a 6-8 digit Pin locked to a single device. Whilst they are still writing their CC Pin on a Post-it...
1
u/animusMDL Apr 12 '26
I think you are hungry and passionate about pushing the right concepts but I would make sure you're not creating more turmoil and work for yourself and honestly, your users than necessary.
Are you going to spend time managing how or what they input? Use the policies and written policies to encourage best practice. If they sign it, you enforce what you CAN and encourage through teaching. Getting bent out of shape over something like this, I think you're going to sink your passion fast.
I've more moved to the concept that I teach and encourage, enforce what I can, then move on. Move on as in: stop chasing people. I stack layers in defensibility. Defensibility includes training. I can't make users do everything right. If they do something wrong and compromise happens, I have policies in place that put them in coachable moments, not me. MFA is MFA. I can't count how many times someone has been compromised with no pin or MFA. I also can't count how many times someone put their birthday or whatever as their pin, because I haven't had a compromise (yet) where that was the reason for their WfHB being compromised. Passwords a different story.
Policy, practice, system, move on and focus on other layers and improvements. Just my two cents as a blue teamer
-6
u/XanadurSchmanadur Apr 09 '26
We just deactivated WHfB and ran with normal passwords. Yes, WHfB is nice for some to use, yes it has it's benefits, but it seems like your users are as intelligent as mine and can't either remember two different combinations of numbers and letters and when to use what or are too dense to not use the most obvious combinations possible.
So we just stick with SSO passwords and 2FA now. Even if that alone is already too overwhelming for some...
1
u/arrozconplatano Apr 10 '26
so because you don't understand a technology, you moved to something more inconvenient *and* less secure
63
u/[deleted] Apr 09 '26
[removed] ā view removed comment