Windows Biometrics Policy Registry Key Location

This article provides a direct overview of the Windows Registry key responsible for storing the configuration parameters of the Windows Biometric Framework (WBF) policies. It outlines the specific path located in the Registry Editor (regedit), explains the essential subkeys, and describes the primary values used to manage biometric login and device functionality across a Windows system.

Primary Registry Path

The configuration parameters for the Windows Biometric Framework Group Policies are stored under the following registry key:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Biometrics

If Group Policies for biometrics have not been configured yet on the system, this key or its subkeys may need to be created manually.


Key Subkeys and Configuration Values

Within the Biometrics key, several values and subkeys control how biometric hardware operates:

1. Global Biometrics Enablement

2. Biometric Credential Provider (Logon Support)

To control whether users can use biometric authentication (such as fingerprint readers or facial recognition) to log on to Windows or elevate UAC prompts, the Credential Provider subkey is used:

3. Domain Account Support

To specifically permit or restrict domain users from logging on with biometric devices:

4. Facial Recognition (Windows Hello Face)

For enhanced anti-spoofing and advanced facial recognition settings: