The Wiert Corner – irregular stream of stuff

Jeroen W. Pluimers on .NET, C#, Delphi, databases, and personal interests

  • My badges

  • Twitter Updates

  • My Flickr Stream

  • Pages

  • All categories

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 1,860 other subscribers

Need to check out the Windows AutoLogonSID registry value and other autologon security features in Windows

Posted by jpluimers on 2024/10/16

On my list of things to look at via [Wayback/Archive] “AutoLogonSID” – Google Search:

So despite autologon.exe being more secure than plain text passwords it is still a risk, though only from privileged code. If anyone can already privileged code on a machine you have far more to worry about (;

To speak with Raymond Chen: [Wayback/Archive] It rather involved being on the other side of this airtight hatchway | The Old New Thing.

So I think it is a fair improvement to configure automatic logon to Windows using autologon.exe than using plan text world readable registry keys, so please consider [Wayback/Archive] Autologon – Windows Sysinternals | Microsoft Docs

Autologon enables you to easily configure Windows’ built-in autologon mechanism. Instead of waiting for a user to enter their name and password, Windows uses the credentials you enter with Autologon, which are encrypted in the Registry, to log on the specified user automatically.

Also, if the shift key is held down before the system performs an autologon, the autologon will be disabled for that logon. You can also pass the username, domain and password as command-line arguments:

autologon user domain password

Note: When Exchange Activesync password restrictions are in place, Windows will not process the autologon configuration.

Anyway: back to the AutoLogonSID. I think that is used with Windows to have a passwordless user automatically logon to a Windows system after boot. I’m not sure yet, so hopefully I have time to dig into that somewhere in the future.

Related blog posts from the past:

–jeroen

 

 

 

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.