locked
Picture password option is lost when joined to a domain

    Question

  • After added my domain user account into win8, picture password doesn't work anymore. There is a message show on the lock screen, it says press and hold Win key and press Power button to login. And in Users page of Control Panel, there is no create picture password and pin password items anymore. How can I get it back? Should I reset the OS?
    Friday, September 30, 2011 1:40 AM

All replies

  • Might be a security feature-I remember asking someone about this at build the other week, and the implication was that those features were disabled (or disableable at least) when a machine was AD joined.  I figured this would be the case, since it's a bit of a security hole for admins.  The real question is, what sort of fine grained control will there be over this?  e.g. will there be a policy template that can allow pin logon, but only with a 6 digit, no common pattern pin? 
    Friday, September 30, 2011 2:22 AM
  • indeed, picture password will be disabled on a domain joined machine. I found someone said there is a registry option can switch it on. And I tried, it indeed works.

    [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System]

    "AllowDomainPicturePassword"=dword:00000001

    "AllowDomainPINLogon"=dword:00000001

    http://social.msdn.microsoft.com/Forums/en-US/windowsdeveloperpreviewgeneral/thread/e0ed59cc-ddd8-4853-88e2-51cd4dbc5608


    Not solve this problem completely, still has another question in following threads.
    Friday, September 30, 2011 6:11 AM
  • But there is still another problem, I still can only use Win button + Power button to logon when the tablet start. How to change back to logon by finger touch on the screen? Is there another registry option to control it?
    Friday, September 30, 2011 6:21 AM
  • Is there someone knows how to fix this problem?

    Friday, October 7, 2011 1:28 PM
  • I just want to make sure I understand your issue.
    You have been able to get the Picture Password to work in a domain environment by changing an
    entry in the registry. 
    Checkk and see if you change the registry Dword value for AllowDomainPicturePassword and AllowDomainPinLogon back to a 0,
    if you can now logon by touch. 

    Let us know if this helps.
    Marilyn
    Wednesday, October 12, 2011 7:58 PM
    Moderator
  • picture password is already works after add these two registry. My problem is when start the tablet, I have to use win button + power button to enter login screen,  either way is use keyboard (ctrl+alt+del), it is inconvenience. But originally it can enter login screen just by finger sweep on screen. How to change it back?
    • Edited by pengweigang Wednesday, October 19, 2011 9:23 AM
    Wednesday, October 19, 2011 9:17 AM