Exclude credential providers
Jump to overview

Policy overview

Key metadata and intent for this policy.

Computer
Category
System > Logon
Supported on
At least Windows Vista

Supported OS tags: Windows10, Windows10RT, Windows11, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista

This policy setting allows the administrator to exclude the specified credential providers from use during authentication. Note: credential providers are used to process and validate user credentials during logon or when authentication is required. Windows Vista provides two default credential providers: Password and Smart Card. An administrator can install additional credential providers for different sets of credentials (for example, to support biometric authentication). If you enable this policy, an administrator can specify the CLSIDs of the credential providers to exclude from the set of installed credential providers available for authentication purposes. If you disable or do not configure this policy, all installed and otherwise enabled credential providers are available for authentication purposes.

Internal name
ExcludedCredentialProviders
Policy ID
2abca9a8f3c8
Elements
1

Registry values

How enabled and disabled states update the registry.

No explicit registry values are set for enabled or disabled states.

Policy elements

Inputs and configuration options exposed by this policy.

ScopeElementTypeRegistry mappingConstraints & behaviorCopy
Computer
Exclude the following credential providers:
ID ExcludedCredentialProviders_Message
text
Path
Software\Microsoft\Windows\CurrentVersion\Policies\System
Value name
ExcludedCredentialProviders
Type
REG_SZ
None
Exclude the following credential providers:
Computer · Type text
Registry mapping
Path
Software\Microsoft\Windows\CurrentVersion\Policies\System
Value name
ExcludedCredentialProviders
Type
REG_SZ
DetailsNone