Policy
Configure device unlock factors
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT
Configure a comma separated list of credential provider GUIDs, such as face and fingerprint provider GUIDs, to be used as the first and second unlock factors. If the trusted signal provider is specified as one of the unlock factors, you should also configure a comma separated list of signal rules in the form of xml for each signal type to be verified. If you enable this policy setting, the user will have to use one factor from each list to successfully unlock. If you disable or do not configure this policy setting, users can continue to unlock with existing unlock options. For more information see: https://go.microsoft.com/fwlink/?linkid=849684
Registry values
How enabled and disabled states update the registry.
No explicit registry values are set for enabled or disabled states.
Policy elements
Inputs and configuration options exposed by this policy.
| Element | Type | Registry mapping | Constraints & behavior |
|---|---|---|---|
First unlock factor credential providers ID MSPassport_UseDeviceUnlock_GroupA | text | HKLM\SOFTWARE\Policies\Microsoft\PassportForWork\DeviceUnlock\GroupA Type REG_SZ | None |
Second unlock factor credential providers ID MSPassport_UseDeviceUnlock_GroupB | text | HKLM\SOFTWARE\Policies\Microsoft\PassportForWork\DeviceUnlock\GroupB Type REG_SZ | None |
Signal rules for device unlock ID MSPassport_UseDeviceUnlock_Plugins | text | HKLM\SOFTWARE\Policies\Microsoft\PassportForWork\DeviceUnlock\Plugins Type REG_SZ | None |
Other policies in this category
Explore related policies at the same level.
- ComputerAllow enumeration of emulated smart card for all usersAt least Windows 10
- ComputerConfigure dynamic lock factorsAt least Windows 10
- ComputerEnable ESS with Supported PeripheralsAt least Windows 11 Version 22H2
- ComputerTurn off smart card emulationAt least Windows 10
- ComputerUse a hardware security deviceAt least Windows 10
- ComputerUse biometricsAt least Windows 10
- ComputerUse certificate for on-premises authenticationAt least Windows 10
- UserUse certificate for on-premises authenticationAt least Windows 10
- ComputerUse cloud trust for on-premises authenticationAt least Windows 10
- ComputerUse PIN RecoveryAt least Windows 10
- UserUse Windows Hello for BusinessAt least Windows 10
- ComputerUse Windows Hello for BusinessAt least Windows 10