Disable the method of local login using a keyboard password?

_KUL 286 Reputation points
2020-11-12T05:37:39.633+00:00

Hello!
My company uses Windows Hello for Business. Additionally, there is a certificate authority with USB tokens. We can login to the Windows operating system using the following methods:

  1. Password from the keyboard
  2. Pin-code
  3. Biometrics
  4. Certificate with USB token

Question: how can I prevent a user from using the keyboard password login method on their computer? Is it possible to manage the registry or group policies? If it is possible to prevent local login using a password, can I save access via RDP? ((If there are rough solutions (non-standard), please specify them as well).

Please take this issue seriously. If you have the opportunity to draw the attention of technical experts. This issue is extremely important and interesting for security in the Windows infrastructure.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,748 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,859 questions
{count} votes

Accepted answer
  1. _KUL 286 Reputation points
    2020-12-03T02:25:39.277+00:00

    An elegant solution!

    1. The Computer must be part of the local corporate AD network.
    2. At the enterprise, we integrate Windows Hello for Business (if by certificates, there will be no problems with RDP) Hybrid model through the new Azure AD Connect model.
    3. In the local AD, in the user profile, set the flag " Smart card is required for interactive login"
      Result: the user will only be able to log in to their workplace using a Smart card (USB, WHfB ...)!

2 additional answers

Sort by: Most helpful
  1. Hannah Xiong 6,231 Reputation points
    2020-11-13T03:20:34.73+00:00

    Hello,

    You are welcome. Thank you so much for your kindly reply.

    So sorry to hear that this is not what we need. As per my understanding, do we want to remove password log in from the Sign-in options?

    39583-4.png

    If so, we could kindly have a check whether the below information is helpful or not.

    https://pureinfotech.com/remove-login-password-windows-10/

    https://www.isunshare.com/windows-10-password/remove-sign-in-password-on-windows-10-computers.html

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Hannah Xiong 6,231 Reputation points
    2020-11-12T08:59:53.21+00:00

    Hello,

    Thank you so much for posting here.

    As per my research, we could choose to disable password login to automatically login without using password or disable the password reveal button on the sign-in screen. Below are the discussions. We could kindly have a check whether it helps.

    How to disable the Password Reveal button on the Sign-in screen on Windows 10
    https://www.windowscentral.com/how-disable-password-reveal-button-sign-screen-windows-10

    How to disable Password login in windows 10
    https://thegeekpage.com/disable-password-login-in-windows-10/

    Automatically Login Without Using Password In Windows 10
    https://www.kapilarya.com/how-to-automatically-login-without-using-password-in-windows-10

    As for the RDP issue, it is suggested that we could turn to the dedicated forum for more professional assistance.
    https://learn.microsoft.com/en-us/answers/topics/windows-remote-desktop-services.html

    For any question, please feel free to contact us.

    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    Best regards,
    Hannah Xiong

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.