enter display name hereenter description hereAssign a default domain for logonThis policy setting specifies a default logon domain, which might be a different domain than the domain to which the computer is joined. Without this policy setting, at logon, if a user does not specify a domain for logon, the domain to which the computer belongs is assumed as the default domain. For example if the computer belongs to the Fabrikam domain, the default domain for user logon is Fabrikam.
If you enable this policy setting, the default logon domain is set to the specified domain, which might be different than the domain to which the computer is joined.
If you disable or do not configure this policy setting, the default logon domain is always set to the domain to which the computer is joined.Exclude credential providersThis policy setting allows the administrator to exclude the specified
credential providers from use during authentication.
Note: credential providers are used to process and validate user
credentials during logon or when authentication is required.
Windows Vista provides two default credential providers:
Password and Smart Card. An administrator can install additional
credential providers for different sets of credentials
(for example, to support biometric authentication).
If you enable this policy, an administrator can specify the CLSIDs
of the credential providers to exclude from the set of installed
credential providers available for authentication purposes.
If you disable or do not configure this policy, all installed and otherwise enabled credential providers are available for authentication purposes.LogonTurn on PIN sign-inThis policy setting allows you to control whether a domain user can sign in using a PIN.
If you enable this policy setting, a domain user can set up and sign in with a PIN.
If you disable or don't configure this policy setting, a domain user can't set up and use a PIN.
Note that the user's domain password will be cached in the system vault when using this feature.Turn off picture password sign-inThis policy setting allows you to control whether a domain user can sign in using a picture password.
If you enable this policy setting, a domain user can't set up or sign in with a picture password.
If you disable or don't configure this policy setting, a domain user can set up and use a picture password.
Note that the user's domain password will be cached in the system vault when using this feature.Allow users to select when a password is required when resuming from connected standbyThis policy setting allows you to control whether or not the user may alter the time before a password is required when a device that supports connected standby's screen turns off.
If you enable this policy setting, a user on a device that supports connected standby may configure the amount of time after the device's screen turns off before a password is required when waking the device. The allowable time is limited by any EAS settings or group policies that affect the maximum idle time before a device locks. In addition, if a password is required when a screensaver turns on, the screensaver timeout will limit the allowable options the user may choose.
If you disable or don't configure this policy setting, the user cannot configure the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password will be required immediately upon the screen turning off.
Note: This policy setting only applies to domain-joined devices that support connected standby.Enter the name of the domainEnter the comma-separated CLSIDs for multiple credential providers
to be excluded from use during authentication.
For example: {ba0dd1d5-9754-4ba3-973c-40dce7901283},{383f1aa4-65dd-45bc-9f5a-ddd2f222f07d}