Information
This policy setting controls the configuration under which the Local Security Authority Subsystem Service (LSASS) will load custom Security Support Provider/Authentication Package (SSP/AP).
The recommended state for this setting is: Disabled.
Vulnerabilities exist where threat actors can intercept logon credentials via SSP/AP. Disabling Custom SSPs and APs to be loaded into LSASS minimizes this vulnerability.
Solution
To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to Disabled :
System > Local Security Authority\Allow Custom SSPs and APs to be loaded into LSASS
Impact:
Custom Security Support Provider/Authentication Packages will not be permitted to load this may impact some legitimate third-party packages.