Policy
Turn off picture password sign-in
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2012, WindowsServer2012R2, WindowsServer2016
This policy setting allows you to control whether a domain user can sign in using a picture password. If you enable this policy setting, a domain user can't set up or sign in with a picture password. If you disable or don't configure this policy setting, a domain user can set up and use a picture password. Note that the user's domain password will be cached in the system vault when using this feature.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\Software\Policies\Microsoft\Windows\System\BlockDomainPicturePassword | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- ComputerAllow users to select when a password is required when resuming from connected standbyAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerAlways use classic logonWindows Server 2003 and versions of Windows from Windows XP Professional through Windows 7.
- ComputerAlways use custom logon backgroundWindows Server 2008 R2 and Windows 7
- ComputerAlways wait for the network at computer startup and logonAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerAssign a default credential providerAt least Windows Server 2016, Windows 10
- ComputerAssign a default domain for logonAt least Windows Vista
- ComputerBlock user from showing account details on sign-inAt least Windows Server 2016, Windows 10
- ComputerDo not display network selection UIAt least Windows Server 2012, Windows 8 or Windows RT
- ComputerDo not display the Getting Started welcome screen at logonWindows 2000 only
- ComputerDo not enumerate connected users on domain-joined computersAt least Windows Server 2012, Windows 8 or Windows RT
- UserDo not process the legacy run listAt least Windows 2000
- ComputerDo not process the legacy run listAt least Windows 2000