18.10.83.1 Ensure 'Configure the transmission of the user's password in the content of MPR notifications sent by winlogon.' is set to 'Disabled'

Information

This policy setting controls whether winlogon includes a user's password in the content of Multiple Provider Router (MPR) notifications. MPR handles communication between the Windows operating system and the installed network providers. MPR checks the registry to determine which providers are installed on the system and the order they are cycled through.

The recommended state for this setting is: Disabled.

MPR is a legacy utility that provides notifications to registered credential managers or network providers when there is a logon event, or a password change event. Although MPR can be used by legitimate applications, the user's password field of these notifications should be empty to prevent abuse by threat actors.

Solution

To establish the recommended configuration via GP, set the following UI path to Disabled :

Computer Configuration\Policies\Administrative Templates\Windows Components\Windows Logon Options\Configure the transmission of the user's password in the content of MPR notifications sent by winlogon.

Note: This Group Policy path may not exist by default. It is provided by the Group Policy template WinLogon.admx/adml that is included with the Microsoft Windows 11 Release 22H2 Administrative Templates v1.0 (or newer).

Note #2: In older Microsoft Windows Administrative Templates, this setting was initially named Enable MPR notifications for the system, but it was renamed starting with the Windows 11 Release 24H2 Administrative Templates.

Impact:

None - this is the default behavior.

Note: If Citrix Workspace App is used in the environment, an exception to this recommendation is needed. For further information, please visit: Cumulative Update 2 (CU2) | Citrix Workspace(TM) app 2402 LTSR for Windows https://docs.citrix.com/en-us/citrix-workspace-app-for-windows/2402-ltsr/whats-new/cumulative-update-2.

See Also

https://workbench.cisecurity.org/benchmarks/26061

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CSCv7|9.2

Plugin: Windows

Control ID: f38d0d90eb8eece57be518153eab21a12103e10ea4d7971cdcd753f7f0e7d13f