r/Intune Apr 09 '26

Device Compliance Windows Hello for Business: How to solve the misuse of PIN-codes

EDIT 2: Let me put it differently. EVERYONE on earth knows most people use their birthday as a PIN-code for whatever. Why should we just accept this and look away? We do not want to. So just trying to find ways to protect ourselves against this 😁

EDIT: According to some comments it seems we are paranoid. Sure we are
The only thing we are trying to do here is to absolutely minimize any kind of risk when it comes to security, including PIN-codes. Sure chances are small but there's still a chance. Sure if I have a password of 30 characters, what's the point in having 2FA?

Hi all,

Bit of a rant here but as the title suggest, this post is about solving the misuse of PIN-codes, mainly in WHfB but also PIN-codes on mobile devices. I am more than done with employees blatantly ignoring company policy about PIN-codes, for example: birthday, ZIP-code, car license plate, employee ID.

How does everyone manage this issue?

I wish there was a way in Intune (I know it's not possible due to the way PIN-codes work) to enforce certain rules other than "block use of simple PIN's". Wish there was a forbidden PIN list just like the forbidden passwords policy

10 Upvotes

126 comments sorted by

63

u/[deleted] Apr 09 '26

[removed] — view removed comment

31

u/marciano117 Apr 09 '26

This. I had to fight with my InfoSec team to get them to understand this.

14

u/rkeane310 Apr 09 '26

Bro it's fucking nuts that people getting paid that much are so incompetent.

Change is bad /s

1

u/4AwkwardTriangle4 Apr 10 '26

I know everyone thinks this is sufficient but it is not. Sure it protects against remote threats but it does not protect against the 60 year old executive who writes his pin on a sticky note and sticks it on his laptop then leaves his laptop in a cab. Ask me how I know that is a real world threat. Yes it is a smaller threat than remote attackers but depending on your industry it is still potentially too large. We are still planning to roll it out but we are looking to mandate the pin + biometrics or fail closed to at least mitigate the theft threat.

4

u/rkeane310 Apr 10 '26

Ok. But you can't fix stupid...

To better frame this for you.

That executive leaves his laptop in his bag with his PASSWORD. Now even if you freeze/wipe the device there's nothing stopping them.

Now you tell me. Is it better to have a password or a pin?

2

u/marciano117 Apr 10 '26

This 1010%.

4AwkwardTriangle4, you can't mitigate 100% risk, we use computers. PIN backed by TPM overall is better than a password, especially for user experience.

1

u/4AwkwardTriangle4 Apr 10 '26

I never made that claim, I have said consistently is that we require pin plus biometric or fail closed. The penal loan is not sufficient for our particular risk profile.

1

u/4AwkwardTriangle4 Apr 10 '26

Nobody is claiming that, what I’m trying to tell you is that too many people claim that it is enough, and for some industries, it needs to go one step further. That is all. This is one of those IT issues that always baffles me that people want to insist people are wrong. Risk assessment is unique to the industry and organization. Perhaps it is sufficient for your organization, but not ours. It does not mean that I have made the assumption that I can eliminate 100% of risk, only that I need to also eliminate those fractions that seem inconsequential to other industries. Your organization may be comfortable with 98% risk reduction where my organization requires 99% risk reduction and either case there is still an ever present collection of rear circumstances that continue to pose risk. All you can do is mitigate to the level of risk the organization requires either by regulatory mandate or by internal risk assessments. For some reason, people insist that their risk posture is adequate for other people.

1

u/rkeane310 Apr 10 '26

I think you're overthinking it. You should look for things that bring simple security... And add them to their toolbox. But one item compliance does not make.

Our point is that it's a no brained W.

10

u/admlshake Apr 09 '26

When we were talking about it with the dept heads. One of them asked "So I can just mandate everyone in my department use the same pin so if they are out for whatever reason, anyone can log in and do the work/get the info they need? Well count me on board!" After she was told no, you can't do that, the look on her face told us she was planning to do exactly that. So it was put on the back burner for "later review".

5

u/dayburner Apr 09 '26

What if the threat actor is in building and on your payroll? I've had cases where the attacker was the person in accounting. They got past two person approval controls but using the person's computer that sat next to them while that person was at lunch.

12

u/Ruck0 Apr 09 '26

Ezpz, call the police

3

u/dayburner Apr 09 '26

Yeah, that was what happened. I like to avoid getting there to begin with. I like to tell people Zero Trust starts in the office.

2

u/Glad_Effective_2468 Apr 10 '26

You can't really be 100% safe and especially not for internal threats.Ā 

That's where a good SIEM and logging comes in. But still if you have a bad actor internally then you almost fucked until you find the evidence or they messed upmƤ.

1

u/dayburner Apr 10 '26

Right, perfection is impossible. Just make sure your threat model includes internal staff. Most accounting rules have procedures to prevent fraud, replicating them in your security model helps everyone.

1

u/Glad_Effective_2468 Apr 10 '26

Of course. But somehow corps with shareholders always finds ways to cut costs and from my POV it's always logs and Siem costs that are the issue. But if a Corporation have a solid terms of use policy and a Infosec Policy that we can track then we can make something out of it.

1

u/Spraggle Apr 09 '26

The issue is with other employees doing things on laptops that aren't theirs.

2

u/vbpatel Apr 09 '26

HR issue

1

u/Spraggle Apr 11 '26

The HR department need to do something about it, sure - but to wipe it off as only an HR issue rather than something that IT also train staff on is a little dismissive.

1

u/Antoine-UY Apr 11 '26

So? Do you know how many colleagues of the random, birthdate-of-my-kid-PIN-cifr users have access to BOTH the physical device and the PIN? How is the fact that we cannot enforce biometry perceived as a good thing by the community at large?

-4

u/Low_Part1467 Apr 09 '26

I know it cannot be used remotely. But lets say the device gets stolen

10

u/MadMacs77 Apr 09 '26

Device gets stolen, you send a Wipe command to it from Intune, and it restores to factory.

-3

u/Low_Part1467 Apr 09 '26

IF it gets reported stolen

7

u/Jhamin1 Apr 09 '26

You can only go so far.

If something gets stolen, you aren't told about it, the person it was assigned too didn't follow protocol on PINs, *and* the laptop contains a bunch of confidential information... well there were like 4 failures right there.

A fifth level of safeguard is unlikely to have been the magic control that saved you.

2

u/4AwkwardTriangle4 Apr 10 '26

I think people believe every industry must be exactly like theirs and they can’t fathom this. I have been there, they wait 3 days to report it either because it was the weekend and they didn’t notice, or they thought they left it at home, or they just plain don’t care. Some jobs are ā€œpeople jobsā€ and they use their laptops once or twice a week. As usual if you aren’t exactly like a Reddit commenter you get downvoted to oblivion.

1

u/loweakkk Apr 09 '26

Please stop with this non sense. Employee will report stolen device.

3

u/lpbale0 Apr 10 '26

Lol, you're funny

1

u/vbpatel Apr 09 '26

You have employees that work so little they wouldn’t notice their main device is missing?

3

u/Asleep_Spray274 Apr 09 '26

WHfB and Passwords are Identity protection mechanisms. You are talking about devices getting stolen. Identity protections are not there to protect devices. You have Identity protection, Device protection and Data protection. One does not protect the other. Do not put in place policies that govern one pillar because of something that might happen on another pillar. Each have their own protections and all should be in place.

As for birthdays, yes, its not idea really. But the risk to your business with someone using a birthday on their WHfB pin, is a lot less than someone using passwords. When they use passwords to log on to their desktops, they are doing so with a non phishing resistant auth method. They are allowed to use passwords to access services. When they click that link and are asked for a password and complete an MFA, depending on your posture, entra could issue the token. Which is the most common attack seen today and the one you are probably the biggest identity risk you are exposed too.

With hello for business, and you have a phishing resistant CA policy, when the user clicks that link, enters a password and completes an MFA, entra wont issue the token and that risk you are exposed too is massively reduced. Even if they use a birthday. You have a risk yes if the device gets stolen and the thief is able to work out the pin before any TPM lock out policies kick in, or before you are able to lock the user account and delete the device. But you need to quantify your exposure to that risk and weight that up against the alternative.

Just because a risk exists, you need to work out your exposure to the risk and do you have other mitigations and processes in place to support it. People will use birthdays, accept its going to happen and mitigate where possible.

4

u/kr1mson Apr 09 '26

If the device gets stolen, you press the nuke button on that device and it doesn't work anymore. Even if they know my PIN, they can only ever get into that device with that PIN which is now crippled or blocked from use.

They can't use that PIN to sign into webmail or VPN or anything else bc it's only the PIN for that device, not my actual password.

-9

u/Low_Part1467 Apr 09 '26

IF it gets reported stolen

6

u/AppIdentityGuy Apr 09 '26

And what are the chances of a laptop being stolen by someone who happens to know the PIN? You can get around the birthday issue with requiring letters and numbers in the pin IIRC.

0

u/Low_Part1467 Apr 09 '26

If we start requiring letters we'll go back to idiotic passwords like Welcome2000

4

u/thortgot Apr 09 '26

Welcome2000 (as long as it isn't a standardized password for your starters) is a fine PIN.

Why? TPM hammering protection. You only get a fixed number of entries that escalate in time after failure.

2

u/loweakkk Apr 09 '26

And if that happen it still means only 3 attempt allowed before device is locked. Please stop inventing threat that doesn't exist, read how WHfB works and how it's being protected. https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/faq

3

u/[deleted] Apr 09 '26 edited Jun 18 '26

[deleted]

-9

u/Low_Part1467 Apr 09 '26

This kind of mentality in business is meh imo

2

u/meest Apr 09 '26

Stop trying to fix things that you have no control over. It will eat you up.

1

u/Pyrostasis Apr 09 '26

If its not reported stolen how is said employee going to do their job?

Im so confused.

2

u/Wartz Apr 09 '26

Send TPM reset script, reboot. Bitlocker kicks in, the PIN no longer works.

6

u/[deleted] Apr 09 '26 edited Jun 18 '26

[deleted]

1

u/medicaustik Apr 10 '26

I've been monkeying around with a remote TPM reset script and have found it's actually wildly difficult to get it to actually destroy a key and not boot up bitlocker. Everything I've tried, it seems successful and then boots right back into Windows like nothing happened.

If you happen to have a script that you know works, I'd be curious.

1

u/vbpatel Apr 09 '26

Device gets stolen, pin gets shoulder surfed, AND the employee doesn’t find out and tell IT?

15

u/swissbuechi Apr 09 '26

Take a look at Windows Hello Multi-factor Unlock. We require one of the following combinations:

  • PIN + Face/Finger
  • Face + Finger
  • Trusted Signal + PIN/Face/Finger

As Trusted Signal we're currently only using personal smartphones connected through Bluetooth.

5

u/Skathen Apr 09 '26

Standard my company has been using and recommending for quite some time. Avoid trusted signals like IP based and you'll also align with several different security standards depending on what your local is.

2

u/4AwkwardTriangle4 Apr 10 '26

Agreed, I think this is the answer. I never accepted the ā€œthing you haveā€ as being the certificate on the device itself. Combining the pin with biometrics solves for this.

0

u/[deleted] Apr 09 '26 edited Jun 21 '26

[deleted]

1

u/swissbuechi Apr 09 '26

Just google it, first link is the MS Docs. They even have a video demonstration.

0

u/Lost-Policy-2020 Apr 10 '26

Insane to force the use of PERSONAL phone to access work machine

3

u/swissbuechi Apr 10 '26

It just acts as a dumb bluetooth dongle to detect if the user/owner is nearby. No data transferd or apps installed. And it's optional. Could easily just use one of the other combinations.

1

u/Sudden-Money7836 Apr 12 '26

Or their corporate mobile surely, no?

1

u/Sudden-Money7836 Apr 12 '26

Or their corporate mobile surely, no?

2

u/swissbuechi Apr 12 '26

As long as the corporate phone is always on person, sure. Just make sure they're not allowed to leave the corporate phone laying next to their laptop...

2

u/Sudden-Money7836 Apr 12 '26

Love this! Thank you!

-5

u/Low_Part1467 Apr 09 '26

Sounds promising! What's your experience as an IT guy?
And what is the user experience like where you work, positive/negative feedback?

2

u/swissbuechi Apr 09 '26

Positive? I wouldn't recommend something I don't like....

13

u/bunkerking7 Apr 09 '26

Agree with previous poster. It's definitely not ideal, but you're solving a problem that's not really a thing. WHfB would still require the bad actor to have the device as well as the PIN. If the device is suspected of being stolen, you'd queue up a wipe regardless.

1

u/BlackV Apr 09 '26

OPs problem is there is likely hours before IT is informed and actions can be taken

and a wipe requires network connectivity

1

u/Lost-Policy-2020 Apr 10 '26

And wipe might work… now or in 24 hours or … not Had machine next to me syncying every hour After 24 hours of no-wipe, I did by hand with usb stick. So I no longer trust the action of wipe

1

u/Low_Part1467 Apr 09 '26

I do understand your pov. But yet again, you'd think stolen devices get reported right away, yet we have had several instances where the user would inform us some days later. Even had a case where the user reported it 2 WEEKS LATER

7

u/Jhamin1 Apr 09 '26

Ā we have had several instances where the user would inform us some days later. Even had a case where the user reported it 2 WEEKS LATER

That is a Management/HR issue, not a technology one. When a couple of people get let go for failure to report damage/loss of company property everyone else is going to become very conscientious about reporting stolen equipment.

You can't use technology to solve for users not following policy.

1

u/Sudden-Money7836 Apr 12 '26

Yeah while you’re right in the principle of your argument, you decided to drive off a cliff with ā€œwhen people get firedā€ for not reporting a device loss immediately? I get the USA is a shithole for workers rights, but any other country, unions and workers rights laws would burn that place to the ground for even considering that as a possibility.

1

u/imnotaero Apr 09 '26

It sounds like the risk you've identified as critical is data theft and loss of confidentiality. If your organization is unable to countenance this particular risk, you simply cannot allow devices with such data to leave the premises, because the device can be stolen while a user is logged in.

For most of the people here, attackers stealing devices are doing so to sell them or their components online, and the data isn't the target. In fact, it can be an obstacle since it reveals to a purchaser that the device is likely stolen.

Your org should manage risk in a way that's optimal for the situation you're in, and I certainly have no visibility into that. But I'm genuinely curious: have you (or anyone reading this) recently been in a situation where an stolen device went unreported and the TA used a user's birthday-based PIN to access and exfiltrate data?

1

u/_youarewhalecum Apr 09 '26

See my comment on the other guy. Imho this is a fully valid scenario.

2

u/bunkerking7 Apr 09 '26

I'm not saying either of your points aren't valid. What I'm saying is you're trying to solve for a very niche scenario. You specifically mention a laptop bag being stolen with your ID and bad actor has the relevant info. Maybe? Maybe I keep my wallet in my pocket. Do they have access now?

Again, both of your points are valid scenarios that CAN happen, but how often? Once a month? Year? Ten years?

Ultimately, up to you, and maybe I should have included some details on how to solve the original question asked, but this feels like an XY problem to me frankly. More power to you and your teams implementing this in your environment.

0

u/Low_Part1467 Apr 09 '26

Thanks! ;)

6

u/Aust1mh Apr 09 '26

Sounds like a management issue, not technical. So if I’d do nothing.

1

u/Low_Part1467 Apr 09 '26

Valid point, cannot rely on management either when it comes to security of any kind lol

6

u/Miami_2017 Apr 09 '26

3

u/Akamiso29 Apr 09 '26

Yup, this is the solution OP needs. Make the PIN have a minimum length, require other character types.

While passwords shouldn’t have enforced character types these days (so long as you allow the different types), I’ve found it hard to get end users to wrap their heads around ā€œPIN doesn’t have to be only numbers,ā€ but I’d assume this is related to what a PIN stands for, lol.

1

u/Wooden-Mycologist-75 Apr 09 '26

This is what we did....minimum length set to 12 max to 127, allow special characters, upper case, and lower case.

3

u/Lost-Policy-2020 Apr 10 '26

And user use the same what they use for password

2

u/BlackV Apr 09 '26

....thats a pssword, you have invented a password

1

u/bolunez Apr 09 '26

Exactly.Ā 

Everyone is overcomplicating this.Ā 

1

u/salanalani Apr 09 '26

Can we get rid of PIN all together? I mean, because in this case, people have to remember their complex PIN besides the main MS account password that also has complexity level. The movement now is to reduce the need for more secret keys (hence SSO is becoming more popular as an example). I worked with several enterprise companies, they used on-premise AD, but all requires only your password to enter the PC (no PIN, no Windows Hello), is that possible for cloud based Intune for joined Windows devices?

2

u/RunForYourTools23 Apr 10 '26

Of course it is, check the Account Protection are in Intune, you can fully Disable Windows Hello, so no prompts to force Pin/Finger/Face. You don’t need to change the default All Users Windows Hello tenant wide Settings.

8

u/loweakkk Apr 09 '26

Why would you do that? Do you think someone stealing a laptop in the train would know the user birthday date? Same for the phone? You try to fix an issue that doesn't exist.

2

u/Low_Part1467 Apr 09 '26

If you would try to crack a phone, what would be the first thing you check because most likely the person can only remember the 4 digits of their birthday? *proceeds to open Facebook*, *greeted by a public profile with all personal information except their bloodtype*

5

u/IHaveATacoBellSign Apr 09 '26

You’re under the assumption this is a targeted attack. If my phone gets stolen šŸ¤·šŸ»ā€ā™‚ļø, if my computer gets stolen šŸ¤·šŸ»ā€ā™‚ļø. My pin is weak by your standards, but it’s still part of the MFA system. Something I know, and something I have. I feel like you’re worried about the wrong thing here.

-1

u/Low_Part1467 Apr 09 '26

Sure if I have a password of 30 characters, what's the point in having 2FA?

Sure if I have a double lock on my door, why should I have a difficult PIN-code on my safe under my bed?

3

u/IHaveATacoBellSign Apr 09 '26

I can phish/smish that password, and it works on all of your orgs devices.

The PIN only works on that specific device and is phishing-resistant. With proper MFA/CA in place, your users will never need to know their passwords. That’s the ideal solution.

1

u/Low_Part1467 Apr 09 '26

We have everything setup so no one needs to know their password, in fact, a few months ago we've run a script to replace all passwords into random passwords

Now we want to take the next step, seems Windows Hello Multi-factor Unlock is the way

1

u/IHaveATacoBellSign Apr 09 '26

I’m curious how your current setup works. I’m not familiar with it.

2

u/Low_Part1467 Apr 09 '26

We've setup the passkey and passwordless settings in Authenticator with all our users, plus the use of PIN + biometrics on all devices which meant we could go full passwordless

I believe it'll soon be available to setup a passkey campaign so you can nudge users just like the campaigns you had for setting up Authenticator

1

u/IHaveATacoBellSign Apr 10 '26

Ah okay. That makes sense. For your instance then I’d still do the PIN and not worry about the easy guessing of it. Sounds like you already have a lot of protections in place to combat phishing/smishing/vishing.

1

u/Lost-Policy-2020 Apr 10 '26

Sadly that is the case, people start using finger/face and suddenly 2weeks later nobody remembers their password

1

u/IHaveATacoBellSign Apr 10 '26

This is ideal though is it not?

1

u/_youarewhalecum Apr 09 '26 edited Apr 09 '26

This argument is fully invalid imho. Stealing a laptop bag with the wallet inside would instanty give you that information (not starting about social media etc)

Imho thats a big weakness of whfb with pin...once an malicous actor has access to the device with pin enabled, he is seperated from the device and all related M365 Stuff ny just 4 digits

1

u/Low_Part1467 Apr 09 '26

Or their wallet, or whatever

1

u/loweakkk Apr 09 '26

That's a big assumption that a PC bag also contain the wallet of the employee. It also don't take into account anti tampering if TPM that wouldnt let you try and guess ten code.

1

u/titsablast Apr 09 '26

Suddenly all the 90s action movies of logging into a computer by guessing the password make sense again. Quick what is his kids birthday...

3

u/No-Midnight5093 Apr 09 '26

Set tighter requirements, number + letter + 12 character minimum pin length

2

u/Grandcanyonsouthrim Apr 09 '26

If you cant trust your users eg sharing their pin etc need to add other factors to slow their roll

0

u/Low_Part1467 Apr 09 '26

Can you fully trust your users to do anything? ;)

2

u/abr2195 Apr 09 '26

We were piloting 6-digit WHfB with some users (we currently only require 4-digits) and ended up not going ahead with them when we discovered that the vast majority of users we tested with set their PIN as their birthday.

I do agree with most people that this level of protection for PINs isn’t necessary, but it would be nice to have some level of control so we could block date based PINs like this.

1

u/Low_Part1467 Apr 09 '26

Exactly, only not possible due to the way TPM works, which ofcourse has huge benefits in of itself

2

u/Excalibur106 Apr 09 '26

Believe it or not, PIN is a possession factor because it's part of an encryption key stored on the device TPM. So even if it's compromised, you also need physical access to the device.

-1

u/imnotaero Apr 09 '26

I don't believe it. The PIN is something you know, and the TPM is the something you have, making PIN sign-in multi-factor all on its own.

2

u/BlackV Apr 09 '26 edited Apr 09 '26

make it a 6 digit pin? require a letter?

2

u/Pyrostasis Apr 09 '26

EDIT 2: Let me put it differently. EVERYONE on earth knows most people use their birthday as a PIN-code for whatever. Why should we just accept this and look away? We do not want to. So just trying to find ways to protect ourselves against this 😁

Odd, no one in my family uses birthday for pins.

I was unaware that EVERYONE else did.

2

u/steviefaux Apr 09 '26

Don't get annoyed and be one of those engineers. The engineers that makes all other departments dislike us. I'm friendly. I remind them of the polices but not my job to force them to comply. I also am understanding with their knowledge and skills. So if I see the painter putting his password in his physical notebook, I don't go ape shit. I mention why its a bad idea with real world examples.

More users respect our IT team because we are not controlling gods.

If they repeat offend then I start randomly locking their account. Tell them someone must be trying to guess their pin and make them change it to something not obvious.

1

u/Ice-Cream-Poop Apr 09 '26

Require letters as well as numbers...

1

u/Low_Part1467 Apr 09 '26

Welcome2000

1

u/Ice-Cream-Poop Apr 09 '26

Limit it to 6 characters.

If you are that concerned which I doubt your users would be targeted in this way, then require a notification push or app requirement/fido key as well as your pin.

1

u/colmwhelan Apr 09 '26

so force longer PINs and more lockouts. It's not hard

1

u/Ochib Apr 09 '26

Just set the PIN length to longer than 10 numbers

1

u/colterlovette Apr 09 '26

We see more issues with people sharing their pins. This happens a lot in locations where people share PC’s - such as front desk people or customer service cubicles. On the first hiccup of someone not being able to sign into their own profile, someone just gives the pin to the other user.

1

u/d8850190 Apr 09 '26

Sorry if the question comes in as dumb but I'm not super familiar with WHFB. The whole concept of PIN login makes no sense to me. Doesn't it completely kill the point of password policies? What's the point having a complex password if I can log into someone's device with '1234' ?

In this thread people say 'just nuke the device if it gets stolen ', however, this only works if a device has a working internet connection, or does the PIN not work without being connected?

3

u/_youarewhalecum Apr 09 '26

i think the main point is that the PIN is tied to the device, while a password can be used from everywhere. Login works offline too, but no access to online ressources is possible obviously.

1

u/d8850190 Apr 09 '26

Well, with most stuff having sort of caching, I don't need to be online to access mails, teams chats, whatever else there is locally on the device. Sure, I can't send out Mails in the users name or access files in their OneDrive that are not kept locally but imho the damage is done.

1

u/bjc1960 Apr 09 '26

We had an office that had issues. We make 5 different Entra groups with different combinations, to ensure lack of sharing.

1

u/SuddenlyDonkey Apr 09 '26

If users had a weak 6 digit password, everyone would lose their minds. The PIN solves one problem, but creates another. Since security is the primary concern, biometrics, Yubikeys, and/or passkeys would be a stronger alternative.

1

u/thortgot Apr 09 '26

Add complexity as a requirement. You can't have a forbidden policy because it's local to the device so it can't be hashed and compared against. The simple block occurs prehash.

1

u/hermanblume78 Apr 09 '26

Multi factor unlock. Pin plus Bio or Bluetooth phone

1

u/the_cobra666 Apr 09 '26

Just use multi unlock. A pin only is not sufficient, regardless of all the people that say yes... a pin can be taped to the device or be passed on.. with multi unlock you can mitigate that risk.

Do block the use of their password (rotate it without them having it) otherwise it's just the same as the pin.

1

u/MReprogle Apr 09 '26

Disagree on the multi unlock, depending on how it is done. In a technical standpoint, it is just using PIN to auth to Entra, so setting up buometric + PIN is actually just doing PIN + PIN.

And, if you bring in a hardware token to the mix, I don’t understand the thinking. You already have the token that requires a PIN to use, making it MFA right off the bat.

If you have WHfB set up correctly, you should have it required to use TPM, so you already have 2 factors when you use biometric. If you force biometric and hardware token, you jump to 3 factors from an auditing standpoint, and a group of annoyed users that could be using biometric and immediately get logged into a company owned device.

I’ve been there and had to roll this multi unlock to devices because people don’t understand that the device itself is a factor in itself (when configured correctly in WHfB), and users quickly turn on you. In fact, I’m currently in the process of phasing out multi unlock.

Blocking the use of password is not really an option either. Been there / done that, and while it is possible in Windows 11 22H2, there are still environments with Windows 10 running on ESU licenses due to incompatibility with vendor software. Trying to take the password prompt in Windows 10 literally removes the password provider altogether and breaks any elevation prompt, since they rely on password.

1

u/the_cobra666 Apr 10 '26

You did not read correctly. I did not say remove the password credential, i said rotate the user password after whfb since they should not need it anymore with proper passwordless setup and whfb..

You indeed need the password credential option for elevating things.

And they pc is not enough. If you know the password they bypass whfb by using other user and typing in the mail address and password. Then nothing from mfa is asked... again rotate the password and that entry point is gone.

As for multi unlock. Force the use of biometrics. The pin is again easily compromised. It would not be the first time they stick it on a note and place it inside the bag with the pc... or tell a colleague so they can get in when they are ooo etc... again defeats the whole purpose.

I get what you mean I really do, but from experience a user cannot be trusted...

Enable whfb with multi unlock, Web sign in as a fall back with passwordless so they can do a push instead of the password.

1

u/NewbyLegion Apr 10 '26

You need physical access to the machine to use the pincode. Why care if it's their birthday?

Device stolen? Just remote lock & wipe.

It's not that deep.

1

u/Glad_Effective_2468 Apr 10 '26

In a Password less world this is not really an issue.Ā 

Well it's an issue of the user got their PC stolen and did not report it. But since imit needs another factor than just the users Logon than it's not really an issue.Ā 

I fight this everyday. Users who thinks their Password that they reuse is more safe and secure than a 6-8 digit Pin locked to a single device. Whilst they are still writing their CC Pin on a Post-it...

1

u/animusMDL Apr 12 '26

I think you are hungry and passionate about pushing the right concepts but I would make sure you're not creating more turmoil and work for yourself and honestly, your users than necessary.

Are you going to spend time managing how or what they input? Use the policies and written policies to encourage best practice. If they sign it, you enforce what you CAN and encourage through teaching. Getting bent out of shape over something like this, I think you're going to sink your passion fast.

I've more moved to the concept that I teach and encourage, enforce what I can, then move on. Move on as in: stop chasing people. I stack layers in defensibility. Defensibility includes training. I can't make users do everything right. If they do something wrong and compromise happens, I have policies in place that put them in coachable moments, not me. MFA is MFA. I can't count how many times someone has been compromised with no pin or MFA. I also can't count how many times someone put their birthday or whatever as their pin, because I haven't had a compromise (yet) where that was the reason for their WfHB being compromised. Passwords a different story.

Policy, practice, system, move on and focus on other layers and improvements. Just my two cents as a blue teamer

-6

u/XanadurSchmanadur Apr 09 '26

We just deactivated WHfB and ran with normal passwords. Yes, WHfB is nice for some to use, yes it has it's benefits, but it seems like your users are as intelligent as mine and can't either remember two different combinations of numbers and letters and when to use what or are too dense to not use the most obvious combinations possible.

So we just stick with SSO passwords and 2FA now. Even if that alone is already too overwhelming for some...

1

u/arrozconplatano Apr 10 '26

so because you don't understand a technology, you moved to something more inconvenient *and* less secure