Last username appears at logon

Risk Level: Low risk vulnerability  Low

Check or Attack Name: Display Last Username

Platforms: Windows NT
Description:

The username of the last user to successfully log in is visible in the Login dialog box. For best security practices, do not display the last username.

Remedy:

WARNING: Incorrectly using Registry Editor may cause severe and irreparable damage and may require you to reinstall your operating system. Internet Security Systems cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk.

Edit the Winlogon registry key to prevent usernames from appearing in the Login dialog box:

  1. Open Registry Editor. From the Windows NT Start menu, select Run, type regedt32, and click OK.
  2. Go to the HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon key.
  3. From the Edit menu, select Add Value to display the Add Value dialog box.
  4. Create a value named DontDisplayLastUserName, of Type REG_SZ. Click OK.
  5. Type 1 as the String value and click OK.
  6. Reboot your computer for this change to take effect.

—OR—

If you have access to the System Policy Editor, see Microsoft Knowledge Base Article "How to: Disable displaying the last username to log in" at http://support.microsoft.com/support/ntserver/serviceware/10141614.asp.

References:

X-Force Logo
Know Your Risks