--- title: Implement Microsoft Passport in your organization (Windows 10) description: You can create a Group Policy or mobile device management (MDM) policy that will implement Microsoft Passport on devices running Windows 10. ms.assetid: 47B55221-24BE-482D-BD31-C78B22AC06D8 keywords: ["identity", "PIN", "biometric", "Hello"] ms.prod: W10 ms.mktglfcycl: deploy ms.sitesec: library author: brianlic-msft --- # Implement Microsoft Passport in your organization **Applies to** - Windows 10 - Windows 10 Mobile You can create a Group Policy or mobile device management (MDM) policy that will implement Microsoft Passport on devices running Windows 10. **Important** The Group Policy setting **Turn on PIN sign-in** does not apply to Windows 10. Use **Microsoft Passport for Work** policy settings to manage PINs. ## Group Policy settings for Passport The following table lists the Group Policy settings that you can configure for Passport use in your workplace. These policy settings are available in **Computer Configuration** > **Policies** > **Administrative Templates** > **Windows Components** > **Microsoft Passport for Work**.
Policy | Options | |
---|---|---|
Use Microsoft Passport for Work |
Not configured: Users can provision Passport for Work, which encrypts their domain password. Enabled: Device provisions Passport for Work using keys or certificates for all users. Disabled: Device does not provision Passport for Work for any user. |
|
Use a hardware security device |
Not configured: Passport for Work will be provisioned using TPM if available, and will be provisioned using software if TPM is not available. Enabled: Passport for Work will only be provisioned using TPM. Disabled: Passport for Work will be provisioned using TPM if available, and will be provisioned using software if TPM is not available. |
|
Use biometrics |
Not configured: Biometrics can be used as a gesture in place of a PIN. Enabled: Biometrics can be used as a gesture in place of a PIN. Disabled: Only a PIN can be used as a gesture. |
|
PIN Complexity | Require digits |
Not configured: Users must include a digit in their PIN. Enabled: Users must include a digit in their PIN. Disabled: Users cannot use digits in their PIN. |
Require lowercase letters |
Not configured: Users cannot use lowercase letters in their PIN. Enabled: Users must include at least one lowercase letter in their PIN. Disabled: Users cannot use lowercase letters in their PIN. |
|
Maximum PIN length |
Not configured: PIN length must be less than or equal to 127. Enabled: PIN length must be less than or equal to the number you specify. Disabled: PIN length must be less than or equal to 127. |
|
Minimum PIN length |
Not configured: PIN length must be greater than or equal to 4. Enabled: PIN length must be greater than or equal to the number you specify. Disabled: PIN length must be greater than or equal to 4. |
|
Expiration |
Not configured: PIN does not expire. Enabled: PIN can be set to expire after any number of days between 1 and 730, or PIN can be set to never expire by setting policy to 0. Disabled: PIN does not expire. |
|
History |
Not configured: Previous PINs are not stored. Enabled: Specify the number of previous PINs that can be associated to a user account that can't be reused. Disabled: Previous PINs are not stored. Note Current PIN is included in PIN history.
|
|
Require special characters |
Not configured: Users cannot include a special character in their PIN. Enabled: Users must include at least one special character in their PIN. Disabled: Users cannot include a special character in their PIN. |
|
Require uppercase letters |
Not configured: Users cannot include an uppercase letter in their PIN. Enabled: Users must include at least one uppercase letter in their PIN. Disabled: Users cannot include an uppercase letter in their PIN. |
|
Remote Passport |
Use Remote Passport Note Applies to desktop only. Phone sign-in is currently limited to select Technology Adoption Program (TAP) participants.
|
Not configured: Remote Passport is disabled. Enabled: Users can use a portable, registered device as a companion device for desktop authentication. Disabled: Remote Passport is disabled. |
Microsoft Passport mode | Azure AD | Active Directory (AD) on-premises (available with production release of Windows Server 2016 Technical Preview) | Azure AD/AD hybrid (available with production release of Windows Server 2016 Technical Preview) |
---|---|---|---|
Key-based authentication | Azure AD subscription |
|
|
Certificate-based authentication |
|
|
|