Allow domain users to log on using biometricsID: oval:org.secpod.oval:def:29337 | Date: (C)2015-10-14 (M)2023-07-14 |
Class: COMPLIANCE | Family: windows |
This policy setting determines whether domain users can log on or elevate User Account Control (UAC) permissions using biometrics.
By default, domain users cannot use biometrics to log on. If you enable this policy setting, domain users can log on to a Windows-based computer using biometrics. Depending on the biometrics you use, enabling this policy setting can reduce the security of users who use biometrics to log on.
If you disable or do not configure this policy setting, domain users will not be able to log on to a Windows-based computer using biometrics.
Note: Users who log on using biometrics should create a password-recovery disk; this will prevent data loss in the event that someone forgets their logon credentials.
Fix:
(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Biometrics!Allow domain users to log on using biometrics
(2) REG: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Biometrics\Credential Provider!Domain Accounts
Platform: |
Microsoft Windows 8.1 |