Allow domain users to log on using biometrics

This policy setting determines whether users with a domain account can log on or elevate User Account Control (UAC) permissions using biometrics.

By default, domain users cannot use biometrics to log on. If you enable this policy setting, domain users can log on to a Windows-based domain-joined computer using biometrics. Depending on the biometrics you use, enabling this policy setting can reduce the security of users who use biometrics to log on.

If you disable or do not configure this policy setting, domain users are not able to log on to a Windows-based computer using biometrics.

Note: Users who log on using biometrics should create a password recovery disk; this will prevent data loss in the event that someone forgets their logon credentials.

Supported on: At least Windows 7

Registry HiveHKEY_LOCAL_MACHINE
Registry PathSOFTWARE\Policies\Microsoft\Biometrics\Credential Provider
Value NameDomain Accounts
Value TypeREG_DWORD
Enabled Value1
Disabled Value0

biometrics.admx

Administrative Templates (Computers)

Administrative Templates (Users)