Bug that forces you to set a pin when installing Windows 10

Anonymous
2018-01-05T17:52:41+00:00

You guys might want to step up your testing efforts. This is a pretty obvious bug IMO. To be clear, I want to use my password and not a pin. But the UI says, "We think you will like it."... well I don't. Normally there is an option to set a pin later.... Well, this goes away permanently if you initially try to authenticate using the Windows Authenticator app.

I am prompted to set a pin, with no button to skip or proceed without one. If I bring up the dialog and cancel, that doesn't help either... You are basically stuck on that screen. I can't finish the installation because the only option to proceed is to create a pin which will replace my password -- I don't want to do that. 

So to be clear:

Install Windows 10 and enter your name and password during installation... You can skip setting a pin.

Install Windows 10 and enter your name and then select authenticate with the authenticator... I successfully authenticate and then I am asked to set a pin. The option to skip is not there as in the first scenario. Starting the process over and entering a password instead does not help. It seems the option to skip is never available again. The only thing I could do was to wipe the install and start over.

Sure I could have set a pin and removed it later, but I didn't want to do that. I don't want it messing with my login. 

Also asking me to file an issue on connect is not going to happen -- sorry. If you guys want to take the time to file it, then go for it. Hopefully you guys will investigate.

Ironically even this forum has a bug... When you edit an issue -- it resets the Windows version and topic.

Windows for home | Windows 10 | Install and upgrade

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2018-05-11T22:28:29+00:00

Hi Arap,

Setting up a pin on your device makes it more secured. One important difference between a password and a Hello PIN is that the PIN is tied to the specific device on which it was set up. Read more in this documentation:

https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-why-pin-is-better-than-password

Thus, you still have option to remove it once you've done setting it up for the first time. Kindly follow the steps below:

  1. Open the Settings app, and click/tap on the Accounts icon.
  2. Select Sign-in options on the left side, and click/tap on the Remove button under PIN on the right side.
  3. Click/tap on Remove to confirm.
  4. Type in your Microsoft account password to verify, and click/tap on OK.

Additionally, you can refer answers mentioned in this thread:

https://answers.microsoft.com/en-us/windows/forum/windows_10-update/i-dont-want-a-pin-number/902c5b3d-42d4-4fc8-b34e-71200e0b362d

Let us know how it turns out.


Note: Microsoft has updated the information in this reply to benefit users facing this issue.


Was this answer helpful?

40+ people found this answer helpful.
0 comments No comments

141 additional answers

Sort by: Oldest
  1. Anonymous
    2019-03-01T18:26:49+00:00

    That response is quite amusing, to say the least; I certainly laughed. Can the PIN be different from the account password, and different on each Windows device they use? Yes. In practice, will the type of "idiot" (your word, not mine) for whom this implementation of PIN was designed actually use a different PIN on each device, and set it to be different from their Microsoft Live account password? No, they will not! You know as well as I do that the "standard idiot" computer user will set the PIN to be the password (because it isn't prevented), use the same one on all his devices (this also is not prevented), and go on with life. Meanwhile, the keylogger has already gotten that PIN, and you know the first thing its owner will do is to try that PIN against the mark's Hotmail account... and it'll work. PIN fail.

    I recently updated Windows 10 on 2 new machines. Once they finished updating and it was time to create accounts, I was required to enter both a password and a PIN for the account; there was no functional way to bypass either one. I have certainly read this whole thread (in fact, I've contributed several comments on it); you do have to enter both a PIN and a password when you create a user account.

    I do not want the PIN to be required (and at the risk of repeating myself yet again, if it allows alphanumeric content, it's a password, not a PIN). I use strong passwords on my Microsoft account, along with 2FA. I likewise have a strong local password. I want the alternate password to be optional. Windows forces me to create one, and will not let me continue with setup until I do so. Windows does not make it user-friendly to switch the login entry from PIN to password, and it seemed to try to sneak itself back to PIN login at least once after a reboot. If I create a dummy PIN, then go in later and try to remove it, Windows complains, like it's some guy named Guido "suggesting" that I use a PIN, while subtly fondling the club he's going to use on my kneecaps if I don't.

    Yes, you don't have to connect the local account with the cloud account. Last time I tried, it took a few mouse clicks and a bit of hunting to find the path to get to that option. Again, the "standard idiot" is not going to go that route, because it won't connect with his OneDrive store or anything else he has attached to his Microsoft account, and it's a PITA for him to find the other option.

    All the way around, it's a marginally useful idea with extremely poor implementation. Is it theoretically more secure? Maybe. In practice? Not really, no. On balance, it's a waste of time and a huge frustration, and isn't really more secure than a good password and 2FA. Forcing me to create a PIN (which isn't really a PIN), and displaying what appears to be an option to bypass it but the bypass doesn't work, is a bug, and it needs to be fixed.

    A few suggestions:

    1. Relabel it from PIN (which insinuates it's purely numerical) to something like "local password", "alternate password", etc. Because that's what it really is. A PIN is what you enter at the ATM or the credit card terminal, because those have only a numeric keypad. If the PIN accepts letters and/or punctuation, it's a password, not a PIN. Label it accordingly.
    2. Use a single login box, not separate password and PIN boxes. The code can check whether the password entered was the main one (i.e. the same one as the linked Microsoft account) or the alternate.
    3. If the user is going to create an alternate password, enforce its "alternate-ness". Require it to be different from the cloud account password. Even figure out a way to enforce uniqueness across all the user's devices, if you still think that's necessary. But it's totally useless if the alternate password can be the same as the Live account password.
    4. For the love of all that is holy, make the alternate password optional. And quit **** about it if the user decides not to use it. Offer it once, accept the decline, and move on, Windows!

    Was this answer helpful?

    10 people found this answer helpful.
    0 comments No comments