UCF STIG Viewer Logo

Windows Ink Workspace must be configured to disallow access above the lock.


Overview

Finding ID Version Rule ID IA Controls Severity
V-220871 WN10-CC-000385 SV-220871r642141_rule Medium
Description
This action secures Windows Ink, which contains applications and features oriented toward pen computing.
STIG Date
Microsoft Windows 10 Security Technical Implementation Guide 2022-04-08

Details

Check Text ( C-22586r642139_chk )
If the following registry value does not exist or is not configured as specified, this is a finding.

Registry Hive: HKEY_LOCAL_MACHINE
Registry Path: \Software\Policies\Microsoft\WindowsInkWorkspace

Value Name: AllowWindowsInkWorkspace
Value Type: REG_DWORD
Value data: 1
Fix Text (F-22575r642140_fix)
Disable the convenience PIN sign-in.

If this needs to be corrected, configure the policy value for Computer Configuration >> Administrative Templates >> Windows Components >> Windows Ink Workspace >> Set "Allow Windows Ink Workspace" to "Enabled” and set Options "On, but disallow access above lock".