Accounts Change PIN for Account in Windows 11


  • Staff
PIN_banner.png

Windows Hello is a more personal, more secure way to get instant access to your Windows 11 devices using a PIN, facial recognition, or fingerprint. You'll need to set up a PIN as part of setting up fingerprint or facial recognition sign-in, but you can also sign in with just your PIN.

These options help make it easier and safer to sign into your PC because your PIN is only associated with one device and it's backed up for recovery with your Microsoft account.

How is a PIN different from (and better than) a password? On the surface, a PIN looks much like a password. A PIN can be a set of numbers, but enterprise policy might allow complex PINs that include special characters and letters, both upper-case and lower-case. Something like t758A! could be an account password or a complex Hello PIN. It isn't the structure of a PIN (length, complexity) that makes it better than a password, it's how it works.
  • PIN is tied to the device
    One important difference between a password and a Hello PIN is that the PIN is tied to the specific device on which it was set up. That PIN is useless to anyone without that specific hardware. Someone who steals your password can sign in to your account from anywhere, but if they steal your PIN, they'd have to steal your physical device too!

    Even you can't use that PIN anywhere except on that specific device. If you want to sign in on multiple devices, you have to set up Hello on each device.
  • PIN is local to the device
    A password is transmitted to the server -- it can be intercepted in transmission or stolen from a server. A PIN is local to the device -- it isn't transmitted anywhere and it isn't stored on the server. When the PIN is created, it establishes a trusted relationship with the identity provider and creates an asymmetric key pair that is used for authentication. When you enter your PIN, it unlocks the authentication key and uses the key to sign the request that is sent to the authenticating server.
  • PIN is backed by hardware
    The Hello PIN is backed by a Trusted Platform Module (TPM) chip, which is a secure crypto-processor that is designed to carry out cryptographic operations. The chip includes multiple physical security mechanisms to make it tamper resistant, and malicious software is unable to tamper with the security functions of the TPM. All Windows 10 Mobile phones and many modern laptops have TPM.

    User key material is generated and available within the Trusted Platform Module (TPM) of the user device, which protects it from attackers who want to capture the key material and reuse it. Because Hello uses asymmetric key pairs, users credentials can't be stolen in cases where the identity provider or websites the user accesses have been compromised.

    The TPM protects against a variety of known and potential attacks, including PIN brute-force attacks. After too many incorrect guesses, the device is locked.
  • PIN can be complex
    The Windows Hello for Business PIN is subject to the same set of IT management policies as a password, such as complexity, length, expiration, and history. Although we generally think of a PIN as a simple four-digit code, administrators can set policies for managed devices to require a PIN complexity similar to a password. You can require or block: special characters, uppercase characters, lowercase characters, and digits.
  • What if someone steals the laptop or phone?
    To compromise a Windows Hello credential that TPM protects, an attacker must have access to the physical device, and then must find a way to spoof the user's biometrics or guess his or her PIN—and all of this must be done before TPM anti-hammering protection locks the device. You can provide additional protection for laptops that don't have TPM by enabling BitLocker and setting a policy to limit failed sign-ins.
  • Why do you need a PIN to use biometrics?
    Windows Hello enables biometric sign-in for Windows 11: fingerprint, iris, or facial recognition. When you set up Windows Hello, you're asked to create a PIN first. This PIN enables you to sign in using the PIN when you can't use your preferred biometric because of an injury or because the sensor is unavailable or not working properly.

    If you only had a biometric sign-in configured and, for any reason, were unable to use that method to sign in, you would have to sign in using your account and password, which doesn't provide you the same level of protection as Hello.
See also:

This tutorial will show you how to change the PIN for your account in Windows 11.


EXAMPLE: PIN sign-in option on sign-in screen

PIN_Sign-in_screen.jpg



Here's How:

1 Open Settings (Win+I).

2 Click/tap on Accounts on the left side, and click/tap on Sign-in options on the right side. (see screenshot below)

Account_PIN-1.png

3 Under Ways to sign in, click/tap on PIN (Windows Hello) to expand it open. (see screenshot below step 4)

4 Click/tap on the Change PIN button to the right of Change your PIN. (see screenshot below)

Account_PIN-2.png

5 Perform the following steps to change your PIN: (see screenshots below)
  1. Type your current PIN at the top.
  2. Type a New PIN you want.
  3. Type the new PIN again to Confirm PIN.
  4. Click/tap on OK.

You can check Include letters and symbols to see PIN requirements and be able to use letters and symbols for your PIN.


Account_PIN-3.png
Account_PIN-4.png

6 You can now close Settings if you like.


That's it,
Shawn Brink


 

Attachments

  • PIN.png
    PIN.png
    340 bytes · Views: 66
Last edited:

tinmar49

Well-known member
Member
VIP
Local time
11:19 AM
Posts
320
Location
UK
OS
W11 pro beta
My pin is somewhat shorter than the 127 charactors allowed, :oops: but it is backed up by a secure boot password. Most of my passwords are in the region of 24 charactors, one of the shortest is PayPal which limits you to 20.
 

My Computers

System One System Two

  • OS
    W11 pro beta
    Computer type
    PC/Desktop
    CPU
    Athlon 3000G
    Motherboard
    Asrock A320M-HDV r4.0
    Memory
    16Gb Crucial DDR4 2400
    Graphics Card(s)
    onboard cpu
    Sound Card
    onboard
    Monitor(s) Displays
    AOC 27
    Screen Resolution
    2560-1440
    Hard Drives
    WD black SN750 M2 500Gb
    PSU
    500W Seasonic core 80+gold non modular
    Case
    Fractal Design Define R2
    Cooling
    front 2 x 120mm rear 100mm stock psu
    Internet Speed
    100/10
    Browser
    Firefox and edge
    Antivirus
    Windows Security and free Malwarebytes
  • Operating System
    W11 pro 64
    Computer type
    PC/Desktop
    Manufacturer/Model
    homebuilt
    CPU
    Ryzen 3200G
    Motherboard
    MSI B450M PRO-VDH
    Memory
    2 x 8Gb Corsair Vengeance LPX 3000 DDR4
    Graphics card(s)
    onboard cpu
    Sound Card
    motherboard
    Monitor(s) Displays
    LG
    Screen Resolution
    1920 x 1080
    Hard Drives
    WD Black M2 SN750 500Gb
    PSU
    Be Quiet 400 semi modular 80+gold
    Case
    Coolermaster Silencio 650
    Cooling
    140mm front, 120 rear Akasa Vegas Chroma AM
    Internet Speed
    100/10
    Browser
    edge/Firefox
    Antivirus
    WD plus Malwarebytes free

Latest Support Threads

Top Bottom