---
title: EnableESSwithSupportedPeripherals enum | Wartiva GraphQL API
description: GPO policy: "Use enhanced anti-spoofing when available" / "Enhanced Sign-in Security" for Windows Hello biometrics.
url: https://wartiva.com/api-docs/types/enable-ess-with-supported-peripherals.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL enum

# `EnableESSwithSupportedPeripherals` enum

GPO policy: "Use enhanced anti-spoofing when available" / "Enhanced Sign-in Security" for Windows Hello biometrics, under Computer Configuration > Administrative Templates > Windows Components > Windows Hello for Business > Biometrics. Controls whether Enhanced Sign-in Security (ESS), which uses hardware-isolated biometric processing, is required. Registry: HKLM\SOFTWARE\Microsoft\Policies\PassportForWork\Biometrics:EnableESSwithSupportedPeripherals (REG_DWORD). Reference: [Windows Hello for Business overview](https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-overview)

## Values

| Enum Value | Description |
|---|---|
| `DISABLED` | Enhanced Sign-in Security disabled (registry value 0). Standard (software-based) biometric sign-in is used; hardware isolation is not required. |
| `ENABLED` | Enhanced Sign-in Security enabled (registry value 1). Hardware-isolated biometric processing is used when supported by the device's biometric hardware. |
| `ENABLED_WITH_PERIPHERAL` | Enhanced Sign-in Security enabled and required with supported peripheral hardware (registry value 2). ESS is enforced and requires compatible secure biometric hardware; biometric sign-in is disabled if unsupported hardware is present. |

## Used by

- [`ComputerAdministrativeTemplates`](https://wartiva.com/api-docs/types/computer-administrative-templates.html) type: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.

## Example

### Example

```json
"DISABLED"

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
