<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-Winlogon" version="10.0.10586.306" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="resources">
    <dependentAssembly>
      <assemblyIdentity name="Microsoft-Windows-Winlogon.Resources" version="10.0.10586.306" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
  </dependency>
  <file name="winlogon.exe" destinationPath="$(runtime.system32)\" sourceName="winlogon.exe" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">5jSeCVsfE1b5A/h8BNIpqDyaXQpT/wd8VZ8Dzk0m7vQ=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="BootRecovery" />
    </categoryMembership>
  </memberships>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Winlogon">
      <registryValue name="EventMessageFile" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\winlogon.exe" />
      <registryValue name="TypesSupported" valueType="REG_DWORD" value="0x00000007" />
      <registryValue name="providerGuid" valueType="REG_SZ" value="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\Application\Wlclntfy">
      <registryValue name="EventMessageFile" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\winlogon.exe" />
      <registryValue name="TypesSupported" valueType="REG_DWORD" value="0x00000007" />
      <registryValue name="providerGuid" valueType="REG_SZ" value="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security">
      <registryValue name="dbe9b383-7cf3-4331-91cc-a3cb16a3b538" valueType="REG_BINARY" value="01000480140000002400000000000000340000000102000000000005200000002002000001020000000000052000000020020000020070000400000000001400FF0F120001010000000000051200000000001800FF0F12000102000000000005200000002002000000002800F70F10000106000000000005500000005EF30FB18164AE04B14CA22914B14C21A65686560000140080000000010100000000000513000000" />
      <registryValue name="206f6dea-d3c5-4d10-bc72-989f03c8b84b" valueType="REG_BINARY" value="01000480140000002400000000000000340000000102000000000005200000002002000001020000000000052000000020020000020048000300000000001400FF0F120001010000000000051200000000001800FF0F1200010200000000000520000000200200000000140080000000010100000000000513000000" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon">
      <registryValue name="DisableBackButton" valueType="REG_DWORD" value="0x00000001" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="description" value="Windows Logon" />
        <string id="description3" value="Policy to allow interactive logon" />
        <string id="displayName" value="Windows Logon" />
        <string id="displayName2" value="InteractiveLogon" />
      </stringTable>
    </resources>
  </localization>
  <migration settingsVersion="0">
    <supportedComponents>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" buildType="release" language="neutral" name="Microsoft-Windows-Winlogon" processorArchitecture="amd64" publicKeyToken="31bf3856ad364e35" settingsVersionRange="0" versionScope="nonSxS" />
        <migXml xmlns="">
          <rules context="System">
            <destinationCleanup>
              <objectSet>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
              </objectSet>
            </destinationCleanup>
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" buildType="release" language="neutral" name="Microsoft-Windows-Winlogon-DL" processorArchitecture="*" settingsVersionRange="0" versionScope="nonSxS" />
        <migXml xmlns="">
          <rules context="System">
            <destinationCleanup>
              <objectSet>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
              </objectSet>
            </destinationCleanup>
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount]</pattern>
                <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
    </supportedComponents>
    <migXml xmlns="">
      <rules context="System">
        <destinationCleanup>
          <objectSet>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
          </objectSet>
        </destinationCleanup>
        <include>
          <objectSet>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [USERINIT]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]</pattern>
            <pattern type="Registry">HKLM\System\CurrentControlSet\Control\Winlogon [TracingControlLevel]</pattern>
          </objectSet>
        </include>
        <merge script="MigXmlHelper.SourcePriority()">
          <objectSet>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ScreenSaverGracePeriod]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeCaption]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [LegalNoticeText]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableLockWorkstation]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [ReportControllerMissing]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [AutoRestartShell]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [PasswordExpiryWarning]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [NoDebugThread]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [DisableCad]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [cachedlogonscount]</pattern>
            <pattern type="Registry">HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon [Shell]</pattern>
          </objectSet>
        </merge>
      </rules>
    </migXml>
  </migration>
  <configuration xmlns="urn:schemas-microsoft-com:asm.v3" xmlns:asmv2="urn:schemas-microsoft-com:asm.v3" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
    <configurationSchema>
      <xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="Microsoft-Windows-Winlogon" targetNamespace="Microsoft-Windows-Winlogon">
        <xsd:element default="2" name="NumberOfInitialSessions" type="xsd:unsignedInt" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="1" name="AutoRestartShell" type="xsd:unsignedInt" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="" name="LegalNoticeCaption" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="" name="LegalNoticeText" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="0" name="PowerdownAfterShutdown" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="10" name="CachedLogonsCount" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="0" name="ForceUnlockLogon" type="xsd:unsignedInt" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="5" name="PasswordExpiryWarning" type="xsd:unsignedInt" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_DWORD" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="0 0 0" name="Background" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="no" name="DebugServerCommand" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="sihost.exe" name="ShellInfrastructure" type="xsd:string" wcm:description="Windows Logon" wcm:displayName="Windows Logon" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon')" wcm:legacyType="REG_SZ" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
      </xsd:schema>
    </configurationSchema>
  </configuration>
</assembly>