18.9.25.1 Ensure 'Allow Custom SSPs and APs to be loaded into LSASS' is set to 'Disabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This policy setting controls the configuration under which the Local Security Authority Subsystem Service (LSASS) will load custom Security Support Provider/Authentication Package (SSP/AP).

The recommended state for this setting is: Disabled.

Rationale:

Vulnerabilities exist where attackers are able to intercept logon credentials via SSP/AP. Disabling Custom SSPs and APs to be loaded into LSASS minimizes this vulnerability.

Impact:

Custom Security Support Provider/Authentication Packages will not be permitted to load this may impact some legitimate third-party packages.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled:

Computer Configuration\Policies\Administrative Templates\System\Local Security Authority\Allow Custom SSPs and APs to be loaded into LSASS

Default Value:

Enabled. (LSA allows custom SSPs and APs to be loaded).