Microsoft deprecates password payload in MPR notifications starting in Windows 11 24H2


FeatureDetails and mitigationDeprecation announced
NPLogonNotify and NPPasswordChangeNotify APIsStarting in Windows 11, version 24H2, the inclusion of password payload in MPR notifications is set to disabled by default through group policy in NPLogonNotify and NPPasswordChangeNotify APIs. The APIs may be removed in a future release. The primary reason for disabling this feature is to enhance security. When enabled, these APIs allow the caller to retrieve a users password, presenting potential risks for password exposure and harvesting by malicious users. To include password payload in MPR notifications, set the EnableMPRNotifications policy to enabled.March 2024


 Source:

 
Since Microsoft likes to use initialisms without explaining them, the Multiple Provider Router (MPR) is the component that handles communication betweek Windows and the various network providers that are installed. Network providers are libraries (DLLs) that allow communication to other types of networks. These network providers can also act as credential managers, so they can receive a copy of the user's credentials. Slipping a rogue network provider (e.g., NPPSpy) into the mix could leak your credentials.
 

My Computer

System One

  • OS
    Windows 11 Pro 25H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Core i7-1260P
    Motherboard
    NUC12WSBi7
    Memory
    64 GB Micron PC4-25600
    Graphics Card(s)
    Intel Iris Xe Graphics
    Sound Card
    on-board Realtek HD Audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840 x 2160
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Crucial MX500 2 TB
    Antivirus
    Microsoft Defender
Back
Top Bottom