windows-itpro-docs/windows/client-management/mdm/policy-csp-admx-credentialproviders.md
2024-08-06 13:15:20 -06:00

11 KiB

title, description, ms.date
title description ms.date
ADMX_CredentialProviders Policy CSP Learn more about the ADMX_CredentialProviders Area in Policy CSP. 08/06/2024

Policy CSP - ADMX_CredentialProviders

[!INCLUDE ADMX-backed CSP tip]

AllowDomainDelayLock

Scope Editions Applicable OS
Device
User
Pro
Enterprise
Education
Windows SE
IoT Enterprise / IoT Enterprise LTSC
Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_CredentialProviders/AllowDomainDelayLock

This policy setting allows you to control whether a user can change the time before a password is required when a Connected Standby device screen turns off.

  • If you enable this policy setting, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.

  • If you disable this policy setting, a user can't change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.

  • If you don't configure this policy setting on a domain-joined device, a user can't change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.

  • If you don't configure this policy setting on a workgroup device, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

[!INCLUDE ADMX-backed policy note]

ADMX mapping:

Name Value
Name AllowDomainDelayLock
Friendly Name Allow users to select when a password is required when resuming from connected standby
Location Computer Configuration
Path System > Logon
Registry Key Name Software\Policies\Microsoft\Windows\System
Registry Value Name AllowDomainDelayLock
ADMX File Name CredentialProviders.admx

DefaultCredentialProvider

Scope Editions Applicable OS
Device
User
Pro
Enterprise
Education
Windows SE
IoT Enterprise / IoT Enterprise LTSC
Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_CredentialProviders/DefaultCredentialProvider

This policy setting allows the administrator to assign a specified credential provider as the default credential provider.

  • If you enable this policy setting, the specified credential provider is selected on other user tile.

  • If you disable or don't configure this policy setting, the system picks the default credential provider on other user tile.

Note

A list of registered credential providers and their GUIDs can be found in the registry at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

[!INCLUDE ADMX-backed policy note]

ADMX mapping:

Name Value
Name DefaultCredentialProvider
Friendly Name Assign a default credential provider
Location Computer Configuration
Path System > Logon
Registry Key Name Software\Policies\Microsoft\Windows\System
ADMX File Name CredentialProviders.admx

ExcludedCredentialProviders

Scope Editions Applicable OS
Device
User
Pro
Enterprise
Education
Windows SE
IoT Enterprise / IoT Enterprise LTSC
Windows 10, version 2004 with KB5005101 [10.0.19041.1202] and later
Windows 10, version 20H2 with KB5005101 [10.0.19042.1202] and later
Windows 10, version 21H1 with KB5005101 [10.0.19043.1202] and later
Windows 11, version 21H2 [10.0.22000] and later
./Device/Vendor/MSFT/Policy/Config/ADMX_CredentialProviders/ExcludedCredentialProviders

This policy setting allows the administrator to exclude the specified credential providers from use during authentication.

Note credential providers are used to process and validate user credentials during logon or when authentication is required.

Windows Vista provides two default credential providers:

Password and Smart Card. An administrator can install additional credential providers for different sets of credentials (for example, to support biometric authentication).

  • If you enable this policy, an administrator can specify the CLSIDs of the credential providers to exclude from the set of installed credential providers available for authentication purposes.

  • If you disable or don't configure this policy, all installed and otherwise enabled credential providers are available for authentication purposes.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace

[!INCLUDE ADMX-backed policy note]

ADMX mapping:

Name Value
Name ExcludedCredentialProviders
Friendly Name Exclude credential providers
Location Computer Configuration
Path System > Logon
Registry Key Name Software\Microsoft\Windows\CurrentVersion\Policies\System
ADMX File Name CredentialProviders.admx

Policy configuration service provider