Introduction
In today's cloud-based environment, managing Windows 11 devices using Intune and Azure Active Directory (AAD) is a common practice. In this article, we will discuss how to configure Windows 11 devices enrolled in Intune to disable the PIN login feature with the 3 failed attempts enforced policy.
Prerequisites
To configure the PIN login settings on Windows 11 devices managed by Intune and Azure Active Directory, make sure you have the following:
- Intune subscription
- Azure Active Directory tenant
- Windows 11 devices enrolled in Intune
Configure PIN Settings in Intune
Follow these steps to configure the PIN settings for Windows 11 devices in Intune:
- Sign in to the Microsoft Endpoint Manager admin center.
- Navigate to Devices > Configuration profiles.
- Click Create profile and select Templates > Windows 10 and later > Security > Authentication > Pin sign-in.
- Provide a name for the profile and select the platform (x64 or x86).
- Under Settings, configure the following options:
- Allow users to enter a PIN: Set this to
No. - Require users to enter a password: Set this to
Yes. - Minimum password length: Set this to the desired length.
- Complexity requirements: Configure the password complexity requirements.
- Enforce password expiration: Set this to
Yesif desired.
Click Next and review the settings on the Summary page. Click Create to save the profile.
Assign the Profile to Devices
After creating the profile, assign it to the appropriate groups or devices:
- Navigate to Devices > All devices.
- Select the devices or groups to which you want to assign the profile.
- Click Assign and select the profile you created.
Enforce the Policy
Once the profile is assigned, it will be enforced on the Windows 11 devices. Users will no longer be able to use a PIN to sign in, and they will be required to enter a password.