enter display name here enter description here Assign a default domain for logon This policy setting specifies a default logon domain, which might be a different domain than the domain to which the computer is joined. Without this policy setting, at logon, if a user does not specify a domain for logon, the domain to which the computer belongs is assumed as the default domain. For example if the computer belongs to the Fabrikam domain, the default domain for user logon is Fabrikam. If you enable this policy setting, the default logon domain is set to the specified domain, which might be different than the domain to which the computer is joined. If you disable or do not configure this policy setting, the default logon domain is always set to the domain to which the computer is joined. Exclude credential providers This policy setting allows the administrator to exclude the specified credential providers from use during authentication. Note: credential providers are used to process and validate user credentials during logon or when authentication is required. Windows Vista provides two default credential providers: Password and Smart Card. An administrator can install additional credential providers for different sets of credentials (for example, to support biometric authentication). If you enable this policy, an administrator can specify the CLSIDs of the credential providers to exclude from the set of installed credential providers available for authentication purposes. If you disable or do not configure this policy, all installed and otherwise enabled credential providers are available for authentication purposes. Logon Turn on PIN sign-in This policy setting allows you to control whether a domain user can sign in using a PIN. If you enable this policy setting, a domain user can set up and sign in with a PIN. If you disable or don't configure this policy setting, a domain user can't set up and use a PIN. Note that the user's domain password will be cached in the system vault when using this feature. Turn off picture password sign-in This policy setting allows you to control whether a domain user can sign in using a picture password. If you enable this policy setting, a domain user can't set up or sign in with a picture password. If you disable or don't configure this policy setting, a domain user can set up and use a picture password. Note that the user's domain password will be cached in the system vault when using this feature. Allow users to select when a password is required when resuming from connected standby This policy setting allows you to control whether or not the user may alter the time before a password is required when a device that supports connected standby's screen turns off. If you enable this policy setting, a user on a device that supports connected standby may configure the amount of time after the device's screen turns off before a password is required when waking the device. The allowable time is limited by any EAS settings or group policies that affect the maximum idle time before a device locks. In addition, if a password is required when a screensaver turns on, the screensaver timeout will limit the allowable options the user may choose. If you disable or don't configure this policy setting, the user cannot configure the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password will be required immediately upon the screen turning off. Note: This policy setting only applies to domain-joined devices that support connected standby. Enter the name of the domain Enter the comma-separated CLSIDs for multiple credential providers to be excluded from use during authentication. For example: {ba0dd1d5-9754-4ba3-973c-40dce7901283},{383f1aa4-65dd-45bc-9f5a-ddd2f222f07d}