Home

Windows 10 Hello for Business PIN complexity not being honored?

%3CLINGO-SUB%20id%3D%22lingo-sub-73480%22%20slang%3D%22en-US%22%3EWindows%2010%20Hello%20for%20Business%20PIN%20complexity%20not%20being%20honored%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-73480%22%20slang%3D%22en-US%22%3EWe%20have%20a%20bunch%20of%20Surface%20pro%20tablets%20in%20the%20process%20of%20being%20upgraded%20to%20Win%2010%201703%20build.%20They%20are%20all%20Azure%20AD%20joined%20devices%2C%20managed%20with%20Intune%20(using%20the%20Intune%20client%20software).%20Post%20upgrade%2C%20users%20are%20being%20required%20to%20change%20their%20PIN%20to%20meet%20new%20complexity%20requirements%20of%206-digits%20minimum%20(we've%20always%20used%204%20digits%20in%20the%20past).%20It's%20a%20complete%20mystery%20to%20me%20where%20this%20requirement%20is%20set%2Fcontrolled%2C%20and%20how%20I%20can%20change%20it%20back%20to%204.%20I%20have%20checked%20our%20Intune%20classic%20admin%20console's%20settings%20here%3A%20Admin-%26gt%3BMDM-%26gt%3BWindows-%26gt%3BWindows%20Hello%20for%20Business%20and%20the%20PIN%20length%20minimum%20is%20set%20to%204%2C%20yet%20so%20I%20am%20at%20a%20loss.%20Any%20guidance%20appreciated!%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-73480%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-75264%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Hello%20for%20Business%20PIN%20complexity%20not%20being%20honored%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-75264%22%20slang%3D%22en-US%22%3EYes%2C%20I'm%20aware%20of%20the%20fact%20that%201703%20is%20pre-release%20and%20not%20yet%20CBB.%20We%20are%20piloting%20it%20for%20a%20client%20that%20is%20anxious%20to%20use%20it%20once%20it's%20released%2C%20and%20they%20will%20be%20using%20it%20for%20a%20fleet%20of%20Surface%20Pro%204%20devices.%20Key-based%20WHB.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-74372%22%20slang%3D%22en-US%22%3ERe%3A%20Windows%2010%20Hello%20for%20Business%20PIN%20complexity%20not%20being%20honored%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-74372%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Bob%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20giving%20the%20rest%20of%20us%20a%20heads%20up%20on%20this.%26nbsp%3B%20I%20must%20ask%2C%20why%20are%20you%20upgrading%20to%201703%20prior%20to%20it%20being%20released%20to%20Current%20Branch%20for%20Business%3F%26nbsp%3B%20It%20is%20definitely%20suggested%20that%20you%20test%201703%2C%20but%20it%20is%20not%20slated%20for%20mass%20deployment%20at%20this%20time.%26nbsp%3B%20In%20fact%2C%20most%20of%20the%20world%20isn't%20on%201703%20yet.%26nbsp%3B%20I%20have%20several%20non-domain%20systems%20at%20home%20that%20are%20being%20serviced%20on%20Current%20Branch%20straight%20from%20Microsoft.%26nbsp%3B%20None%20have%20been%20upgraded%20to%201703.%26nbsp%3B%20One%20of%20these%20is%20a%20Surface%20pro%204.%26nbsp%3B%20I%20believe%20it%20finally%20started%20downloading%20the%20bits%20for%20it%20in%20the%20background.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20just%20testing%2C%20this%20is%20exactly%20why%20you%20should%20be%20doing%20that.%26nbsp%3B%20Providing%20this%20feedback%20is%20crucial%20in%20making%20sure%20these%20issues%20don't%20exist%20when%201703%20is%20CBB%20ready.%26nbsp%3B%20Thanks%20for%20taking%20the%20time.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAre%20you%20using%20Key-Based%20or%20Cert-Based%20WH4B%3F%26nbsp%3B%20It%20doesn't%20matter%2C%20but%20I'm%20curious!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E-LvilleSystemsJockey%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor
We have a bunch of Surface pro tablets in the process of being upgraded to Win 10 1703 build. They are all Azure AD joined devices, managed with Intune (using the Intune client software). Post upgrade, users are being required to change their PIN to meet new complexity requirements of 6-digits minimum (we've always used 4 digits in the past). It's a complete mystery to me where this requirement is set/controlled, and how I can change it back to 4. I have checked our Intune classic admin console's settings here: Admin->MDM->Windows->Windows Hello for Business and the PIN length minimum is set to 4, yet so I am at a loss. Any guidance appreciated!
2 Replies

Hi Bob,

 

Thanks for giving the rest of us a heads up on this.  I must ask, why are you upgrading to 1703 prior to it being released to Current Branch for Business?  It is definitely suggested that you test 1703, but it is not slated for mass deployment at this time.  In fact, most of the world isn't on 1703 yet.  I have several non-domain systems at home that are being serviced on Current Branch straight from Microsoft.  None have been upgraded to 1703.  One of these is a Surface pro 4.  I believe it finally started downloading the bits for it in the background.

 

If you are just testing, this is exactly why you should be doing that.  Providing this feedback is crucial in making sure these issues don't exist when 1703 is CBB ready.  Thanks for taking the time.

 

Are you using Key-Based or Cert-Based WH4B?  It doesn't matter, but I'm curious!

 

-LvilleSystemsJockey

Yes, I'm aware of the fact that 1703 is pre-release and not yet CBB. We are piloting it for a client that is anxious to use it once it's released, and they will be using it for a fleet of Surface Pro 4 devices. Key-based WHB.
Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
46 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
13 Replies