Windows-itpro-docs: "After too many incorrect guesses, the device is locked."

Created on 16 Apr 2020  Â·  2Comments  Â·  Source: MicrosoftDocs/windows-itpro-docs

How many times is too many?

After a device is locked, what options do Intune/MDM admins have to "unlock" it?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

hello-for-business

Most helpful comment

If the key is generated in a TPM2.0, the hardware anti-hammering behavior of the TPM allows 32 PIN attempts before locking out. Once the TPM locks out, there is a cool down period of 10 minutes before another attempt can be made. The OS will allow 5 attempts before forcing the user to reboot to allow more attempts.

TPM1.2 behavior is manufacturer specific.

If a TPM is locked out it can be reset by an admin, but this will destroy all of the keys protected by the TPM. For more information about TPM lockout behavior see https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/manage-tpm-lockout

All 2 comments

If the key is generated in a TPM2.0, the hardware anti-hammering behavior of the TPM allows 32 PIN attempts before locking out. Once the TPM locks out, there is a cool down period of 10 minutes before another attempt can be made. The OS will allow 5 attempts before forcing the user to reboot to allow more attempts.

TPM1.2 behavior is manufacturer specific.

If a TPM is locked out it can be reset by an admin, but this will destroy all of the keys protected by the TPM. For more information about TPM lockout behavior see https://docs.microsoft.com/en-us/windows/security/information-protection/tpm/manage-tpm-lockout

Tested this with VM.

  • After 4 attempts - passphrase challenge
  • After 5 attempts - require OS restart
  • After 9 attempts - passphrase challenge after 30 secs
  • After 10 attempts - require OS restart
  • After 14 attempts - passphrase challenge after 1 min
  • After 15 attempts - require OS restart
  • After 19 attempts - passphrase challenge after 2 mins
  • After 20 attempts - require OS restart
  • After 24 attempts - passphrase challenge after 5 mins
  • After 25 attempts - require OS restart
  • After 29 attempts - passphrase challenge after 10 mins
  • After 30 attempts - require OS restart
  • After 32 attempts - PIN locked down for 2 hrs contiguous powered on.
Was this page helpful?
0 / 5 - 0 ratings

Related issues

Ludwig1770 picture Ludwig1770  Â·  3Comments

iadgovuser1 picture iadgovuser1  Â·  3Comments

arcotek-ltd picture arcotek-ltd  Â·  3Comments

RAJU2529 picture RAJU2529  Â·  3Comments

illfated picture illfated  Â·  3Comments