4.11.50.1 (L1) Ensure 'Enable MPR notifications for the system' is set to 'Disabled'

Information

This policy setting controls whether winlogon sends Multiple Provider Router (MPR) notifications. MPR handles communication between the Windows operating system and the installed network providers. MPR checks the registry to determine which providers are installed on the system and the order they are cycled through.

The recommended state for this setting is: Disabled

MPR is a legacy utility that provides notifications to registered credential managers or network providers when there is a logon event or a password change event. Although this functionality can be used by legitimate applications, it can also be abused by attackers to harvest logon information.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :

Administrative Templates\Windows Components\Windows Logon Options\Enable MPR notifications for the system

Impact:

Winlogon will not send Multiple Provider Router (MPR) notifications on the system. This setting may also cause issues with reconnecting to drives.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: 88fc63366db0a6db5c723b1407aea342bb596a3f49559544a8f5a0a3ed48eeb8