In a word: scope.

It can be as secure — perhaps even more secure — because it’s used in a different way.
You can also choose to increase a PIN’s security by using some of the same techniques we use for passwords in general.

One PIN per PC
Your Windows PIN works only on the one computer where you set it up. A thief would need both the PIN and the computer itself, so a faraway hacker can’t use it. Want more strength? Make your PIN longer, or make it password-like with letters and symbols.
The big difference: scope
The biggest difference between using a PIN and a password to sign in to your computer is that the PIN only works on the computer on which you set it up.
If someone knows your PIN, they’ll be able to sign in to that device, but only if they also have physical access to the computer. If they can do that, your machine isn’t physically secure. With or without your PIN, anyone who has physical access to your machine can use any number of techniques to get at its contents.
There are at least two instances in which having an “easy” or automatic sign-in puts you at additional risk.
- If you have saved logins or passwords in your browser, anyone can walk up to your computer and access those sites or credentials.
- If you use BitLocker to encrypt your data, logging in allows access to that data.
In those cases, the ability to log in using that easy-to-remember PIN could allow access, but it still requires physical access to the computer.
To an overseas hacker, a PIN is pretty much useless… unlike your password.
Help keep it going by becoming a Patron.
A PIN can be more secure
Many people fear a type of malware known as a keylogger.
When installed, keyloggers secretly record your keystrokes (and possibly more) and send the recording to hackers. Log in to a website, for example, and the keylogger records both your username and password. Only something like multi-factor authentication can save you.
If you use a PIN to sign in to your computer, however, they can record anything they like, and it won’t get them anywhere. The PIN only works on that device, which a remote hacker has no access to. Even if you use a Microsoft account to sign in to your computer, that PIN is useless everywhere else.
There’s an argument that using a PIN is more secure, since you never type your Microsoft account password into your machine. Keyloggers can’t log what you never enter.
Strength: treat it like a password
If a four-digit PIN still makes you uncomfortable, consider treating it like a password. There are two approaches.
The first is to make it longer. There’s nothing that says you have to use your four-digit ATM-style PIN as your Windows sign-in PIN. Use something longer — much longer, if you like. Just adding a single digit to your regular PIN makes it ten times stronger. A six-digit PIN is one hundred times as strong.
The second is to include letters and symbols in your PIN.

A PIN with letters and symbols is nothing more than a password. This, then, would act as an alternative password used to sign in only to this specific device.
PINs are convenient
Using a PIN is, I believe, intended to make signing in to your Microsoft account more convenient. As we’ve seen, it may make it a little more secure because you don’t type in your actual password. If you log in with a PIN, you’re free to make your Microsoft account password long and complex. This strengthens the security of your online accounts, like Outlook.com email, OneDrive online storage, and more.
Alternatively, if you configured your Microsoft account to be password-less, meaning you’re using only passkeys or other forms of authentication, you may be required to set up a PIN (or facial or fingerprint recognition) as the primary way to sign in to your computer. Your online accounts are more secure (there’s no password to be compromised), but PINs move from a convenience to a potential requirement.
What if I forget my PIN?
When you sign in, there’s a link you can click on if you’ve forgotten your PIN.

This will take you online and have you authenticate with your Microsoft account in another way.

In my case, I’m offered:
- Windows Hello: the face, fingerprint, PIN, or security key option. You’ve forgotten the PIN, but if you previously set up one of the others (and I recommend you do), it can be used.
- Your password, if your account has one. (Meaning it’s not a “passwordless” account.)
- Email to an alternate recovery account, if one has been set up.
All of these are much like the Microsoft account recovery process. Once authenticated, you’ll be signed into your computer and given the opportunity to set a PIN that you’ll (hopefully) remember.
Do this
Consider adding a PIN to your Windows sign-in. Within Settings, search for “PIN”, and it’ll be in a group of settings called “Windows Hello”.
Subscribe to Confident Computing! Less frustration and more confidence, solutions, answers, and tips in your inbox every week.

Now you can use letters and special characters in your PIN. By definition, it’s no longer a PIN, Personal Identification Number, it’s a PIP Personal Identification Password or Passphrase. 😉
You can count on Microsoft for ridiculous naming conventions.