Require Trusted Path for Credential Entry

๐Ÿ”’ Secure Bits ๐Ÿ’ก
๐—ง๐—ต๐—ฒ โ€œ๐—ง๐—ฟ๐˜‚๐˜€๐˜๐—ฒ๐—ฑ ๐—ฃ๐—ฎ๐˜๐—ตโ€ ๐—ฃ๐—ผ๐—น๐—ถ๐—ฐ๐˜† ๐—ง๐—ต๐—ฎ๐˜ ๐—•๐—ฟ๐—ผ๐—ธ๐—ฒ ๐—ข๐—ข๐—•๐—˜

This was a weird oneโ€”and it took a while to figure out.

I was working on my ๐˜€๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ฏ๐—ฎ๐˜€๐—ฒ๐—น๐—ถ๐—ป๐—ฒ๐˜€ and came across a recommendation to enable:
๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ถ๐˜ต๐˜ฆ๐˜ณ ๐˜Š๐˜ฐ๐˜ฏ๐˜ง๐˜ช๐˜จ๐˜ถ๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ฐ๐˜ฏ๐˜ˆ๐˜ฅ๐˜ฎ๐˜ช๐˜ฏ๐˜ช๐˜ด๐˜ต๐˜ณ๐˜ข๐˜ต๐˜ช๐˜ท๐˜ฆ ๐˜›๐˜ฆ๐˜ฎ๐˜ฑ๐˜ญ๐˜ข๐˜ต๐˜ฆ๐˜ด๐˜ž๐˜ช๐˜ฏ๐˜ฅ๐˜ฐ๐˜ธ๐˜ด ๐˜Š๐˜ฐ๐˜ฎ๐˜ฑ๐˜ฐ๐˜ฏ๐˜ฆ๐˜ฏ๐˜ต๐˜ด๐˜Š๐˜ณ๐˜ฆ๐˜ฅ๐˜ฆ๐˜ฏ๐˜ต๐˜ช๐˜ข๐˜ญ ๐˜œ๐˜ด๐˜ฆ๐˜ณ ๐˜๐˜ฏ๐˜ต๐˜ฆ๐˜ณ๐˜ง๐˜ข๐˜ค๐˜ฆ
๐Ÿ› ๏ธ โ€œ๐—ฅ๐—ฒ๐—พ๐˜‚๐—ถ๐—ฟ๐—ฒ ๐˜๐—ฟ๐˜‚๐˜€๐˜๐—ฒ๐—ฑ ๐—ฝ๐—ฎ๐˜๐—ต ๐—ณ๐—ผ๐—ฟ ๐—ฐ๐—ฟ๐—ฒ๐—ฑ๐—ฒ๐—ป๐˜๐—ถ๐—ฎ๐—น ๐—ฒ๐—ป๐˜๐—ฟ๐˜†โ€

Sounded good, tested fine, so I rolled it out to production.

Then the ๐˜€๐˜๐—ฟ๐—ฎ๐—ป๐—ด๐—ฒ ๐—ฏ๐˜‚๐—ด ๐—ต๐—ถ๐˜โ€ฆ
Admins started reporting broken OOBE screens for local administrator accounts. No matter what we triedโ€”every path led back to the same ๐˜‚๐—ป๐˜‚๐˜€๐—ฎ๐—ฏ๐—น๐—ฒ ๐˜€๐—ฐ๐—ฟ๐—ฒ๐—ฒ๐—ป.

๐—ง๐˜‚๐—ฟ๐—ป๐˜€ ๐—ผ๐˜‚๐˜:
๐Ÿ”น The policy blocked the UAC secure desktop prompt thatโ€™s supposed to show up
๐Ÿ”น That left us stuck in OOBE with no way to proceed

โœ… Disabling the policy fixed it immediately.

๐Ÿ’ก๐—™๐˜‚๐—ป ๐˜๐˜„๐—ถ๐˜€๐˜:ย Microsoft later clarified they ๐—ป๐—ฒ๐˜ƒ๐—ฒ๐—ฟ ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ถ๐—ฎ๐—น๐—น๐˜† ๐—ฟ๐—ฒ๐—ฐ๐—ผ๐—บ๐—บ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฑ this setting. (ehm…gpedit.msc…). But it used to be recommended for some time by other agencies.

So โ€” if you’re building or reviewing your baselines, ๐—ธ๐—ฒ๐—ฒ๐—ฝ ๐—ฎ๐—ป ๐—ฒ๐˜†๐—ฒ ๐—ผ๐—ป ๐˜๐—ต๐—ถ๐˜€ ๐—ผ๐—ป๐—ฒ.
It might save you a few hours of unexpected troubleshooting.

Have you ever enabled this setting? Let me know ๐Ÿ‘‡