Configure the transmission of the user's password in the content of MPR notifications sent by winlogon.

Information

This policy controls whether the user's password is included in the content of MPR notifications sent by winlogon in the system.

If you disable this setting or do not configure it winlogon sends MPR notifications with empty password fields of the user's authentication info.

If you enable this setting winlogon sends MPR notifications containing the user's password in the authentication info.

Solution

Policy Path: Windows Components\Windows Logon Options
Policy Setting Name: Configure the transmission of the user's password in the content of MPR notifications sent by winlogon.

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-24h2-security-baseline/ba-p/4252801

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: 8dbb9b0ea7cf694235fb44d7ed502c1b2f332e4d292f3e87d904df98f77cf42d