Paolo Matarazzo 3607d17bf7 update
2025-04-28 07:01:54 -04:00

1.4 KiB

author, ms.author, ms.date, ms.topic
author ms.author ms.date ms.topic
paolomatarazzo paoloma 03/12/2024 include

History

This setting specifies the number of past PINs that can be associated to a user account that can't be reused. This policy enhances security by ensuring that old PINs are not reused continually. The value must be between 0 to 50 PINs. If this policy is set to 0, then storage of previous PINs is not required.

The default value is 0.

Note

PIN history is not preserved through PIN reset.

Path
CSP ./Device/Vendor/MSFT/PassportForWork/{TenantId}/Policies/PINComplexity/devicetenantidpoliciespincomplexityhistory

./User/Vendor/MSFT/PassportForWork/{TenantId}/Policies/PINComplexity/usertenantidpoliciespincomplexityhistory
GPO Computer Configuration > Administrative Templates > System > PIN Complexity

Important

PIN history is not supported on:

  • Devices with Enhanced Security Settings (ESS) enabled, since Windows Hello uses Virtualization-based Security (VBS) to isolate credentials.
  • Starting with Windows 11, version 24H2, on all devices that have VBS enabled.