SSPR with CIS hardening for Windows 10

TRON Aymeric 0 Reputation points
2023-02-20T14:44:03.79+00:00

SSPR is working well but i have to use CIS hardening for Microsoft Windows 10 Enterprise (1.12.0).

Now, the SSPR on windows 10 login page don't work anymore : a session seems to open and close immediatly.

Can you help me ? what kind of rights are used to open a SSPR session ?

(i've already allowed :

  • AllowPasswordReset
  • DontDisplayLastUserName
  • NoLockScreen
  • DisableLockScreenAppNotifications)

( Followed https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-sspr-windows )

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
12,077 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
3,022 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Limitless Technology 44,666 Reputation points
    2023-02-21T17:01:16.7533333+00:00

    Hi. Thank you for your question and reaching out. I’d be more than happy to help you with your query

    To open a SSPR session, you will need to make sure that the user has the appropriate rights. These rights can be configured through the Local Security Policy on the Windows 10 machine. The rights you need to enable are: Change Password, Force Password Change on Logon, and Set Password. Additionally, you will need to make sure that the user is allowed to logon locally, as well as have rights to the SSPR service itself. Lastly, you will need to ensure that the user is able to authenticate with the associated authentication provider. Once all of these rights are set, the user should be able to open a SSPR session.

    If the reply was helpful, please don’t forget to upvote or accept as answer, thank you.

    0 comments No comments

  2. Limitless Technology 44,666 Reputation points
    2023-02-21T17:01:28.23+00:00

    Double post

    0 comments No comments

  3. TRON Aymeric 0 Reputation points
    2023-03-03T15:48:56.0333333+00:00

    After varous tests, i have concluded that the option "Prevent non-admin users from installing packaged Windows apps" need to be desactivated.

    I don"t know why : SSPR is a packaged indows app ?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.