How to Specify Minimum PIN Length for BitLocker Startup in Windows 10
Information
When you turn on BitLocker for the operating system drive with a compatible TPM, you can choose to unlock the OS drive at startup with a PIN.
Originally, BitLocker allowed from 4 to 20 characters for a PIN. Starting with Windows 10 version 1703, the minimum length for the BitLocker PIN was increased to 6 characters to better align with other Windows features that leverage TPM 2.0. To help organizations with the transition, beginning with Windows 10 version 1709 and Windows 10 version 1703 with the October 2017 Fall Cumulative Update installed, the BitLocker PIN length is 6 characters by default, but it can be reduced to 4 characters. If the minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.
The Configure minimum PIN length for startup policy is used to set a minimum PIN length when you use an unlock method that includes a PIN. This policy setting is applied when you turn on BitLocker for the OS drive. The startup PIN must have a minimum length of 4 digits, and it can have a maximum length of 20 digits. By default, the minimum PIN length is 6.
This tutorial will show you how to specify a minimum length for a TPM startup PIN used with BitLocker in Windows 10.
You must be signed in as an administrator to specify a minimum PIN length for BitLocker startup.
Note
CONTENTS:
- Option One: Specify Minimum PIN Length for BitLocker Startup in Local Group Policy Editor
- Option Two: Specify Minimum PIN Length for BitLocker Startup in Registry Editor
Note
Local Group Policy Editor is only available in the Windows 10 Pro, Enterprise, and Education editions.
1. Open the Local Group Policy Editor.
2. In the left pane of Local Group Policy Editor, navigate to the location below. (see screenshot below)
Computer Configuration\Administrative Templates\Windows Components\BitLocker Drive Encryption\Operating System Drives
3. In the right pane of Operating System Drives in Local Group Policy Editor, double click/tap on the Configure minimum PIN length for startup policy to edit it. (see screenshot above)
4. Do step 5 (specify) or step 6 (default) below for what you would like to do.
A) Select (dot) Enabled, enter a number between 4 to 20 in Minimum characters for what you want, click/tap on OK, and go to step 7 below. (see screenshot below)
Note
If minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.
A) Select (dot) Not Configured or Disabled, click/tap on OK, and go to step 7 below. (see screenshot below)
NOTE: Not Configured is the default setting.
7. When finished, you can close the Local Group Policy Editor if you like.
1. Press the Win+R keys to open Run, type regedit into Run, and click/tap on OK to open Registry Editor.
2. Navigate to the key below in the left pane of Registry Editor. (see screenshot below)
Note
If you do not have a FVE key, then right click on the Microsoft key, click/tap on New, click/tap on Key, type FVE for the name, and press Enter.
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE
3. Do step 4 (specify) or step 5 (default) below for what you would like to do.
A) In the right pane of the FVE key, right click or press and hold on the MinimumPIN DWORD to modify it. (see screenshot below step 2)
B) Select (dot) Decimal, enter a number between 4 to 20 for what you want, click/tap on OK, and go to step 6 below. (see screenshot below)
Note
If minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.
A) In the right pane of the FVE key, right click or press and hold on the MinimumPIN DWORD, and click/tap on Delete. (see screenshot below step 2)
B) Click/tap on Yes to confirm, and go to step 6 below. (see screenshot below)
6. You can now close Registry Editor if you like.
That's it,
Shawn
Related Tutorials
- How to Turn On or Off BitLocker for Operating System Drive in Windows 10
- How to Enable or Disable Standard Users from Changing BitLocker PIN or Password in Windows 10
- How to Enable or Disable Enhanced PINs for BitLocker Startup in Windows 10
- How to Change BitLocker Startup PIN in Windows 10
- How to Add or Remove Change BitLocker PIN Context Menu in Windows 10
- How to Unlock an OS Drive Encrypted by BitLocker in Windows 10