further reading on this, it may not be a definite security deficiency, IF windows still counts the login attempts by EITHER password OR pin, as failed attempts, and locks the machine up upon appropriate number of attempts.
BUT, i SHOULD have the option to limit attempts to just be PIN, and not password..