Windows 11 must be configured to require a minimum pin length of six characters or greater.
An XCCDF Rule
Description
Windows allows the use of PINs as well as biometrics for authentication without sending a password to a network or website where it could be compromised. Longer minimum PIN lengths increase the available combinations an attacker would have to attempt. Shorter minimum length significantly reduces the strength.
- ID
- SV-253401r991589_rule
- Version
- WN11-CC-000260
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the policy value for Computer Configuration >> Administrative Templates >> System >> PIN Complexity >> "Minimum PIN length" to "6" or greater.