This policy setting determines whether users with a domain account can log on or elevate User Account Control (UAC) permissions using biometrics.
By default, domain users cannot use biometrics to log on. If you enable this policy setting, domain users can log on to a Windows-based domain-joined computer using biometrics. Depending on the biometrics you use, enabling this policy setting can reduce the security of users who use biometrics to log on.
If you disable or do not configure this policy setting, domain users are not able to log on to a Windows-based computer using biometrics.
Note: Users who log on using biometrics should create a password recovery disk; this will prevent data loss in the event that someone forgets their logon credentials.
|Registry Path||SOFTWARE\Policies\Microsoft\Biometrics\Credential Provider|
|Value Name||Domain Accounts|