All settings are registry values under HKLM\SOFTWARE\CodeB (mostly Config and CP) and HKLM\SOFTWARE\Aloaha. On 64-bit Windows the CodeB components read them from the 32-bit view: HKLM\SOFTWARE\WOW6432Node\CodeB\…. Switches take 0 or 1; a missing value is created with its default the first time it is read.
How settings are stored
- Location. Unless a table says otherwise, paths are relative to
HKLM\SOFTWARE\CodeB\, andConfigisHKLM\SOFTWARE\CodeB\Config. - 32-bit view. On 64-bit Windows use
HKLM\SOFTWARE\WOW6432Node\CodeB\…andHKLM\SOFTWARE\WOW6432Node\Aloaha\…. The exceptions are the filter values underHKLM\SOFTWARE\Aloaha\CP, which live in the normal 64-bit view. - Types. On/off switches are DWORD or string values
0/1. Paths and texts are strings. - Defaults. The provider writes a missing value with its default when it first reads it, so after the first logon screen most values are visible and can be edited.
- When changes apply. Tile settings apply the next time the logon or lock screen opens; settings of the CodeB service apply within its next check or after a service restart.
- Deployment. Group Policy Preferences,
.regfiles, SCCM/Intune or scripts. CodeB ships no ADMX template; the values are listed here.
Logon tile — Config
| Value | Default | Effect |
|---|---|---|
HideUsernameField | 0 | 1 hides the Username field on the CodeB tile. |
HideOptionalSecretField | 0 | 1 hides the Optional Secret or Password field. Without it, the field is also hidden automatically when no linked token needs it. Has no effect while AlwaysShowOptionalSecretField or Use_AD_altSecurityIdentities is 1. |
AlwaysShowOptionalSecretField | 0 | 1 always shows the Optional Secret or Password field. It is also shown whenever Use_AD_altSecurityIdentities is 1. |
HideTOTPField | 0 | 1 hides the TOTP or PIN field. |
HideShowCharacters | 0 | 1 hides the Display typed values check box. |
HideExtraTile | 0 | 1 hides the extra “Other User” tile, so only the tiles of known users are shown. |
ActiveField | 3 | Field that has the focus: 1 Username, 2 Optional Secret or Password, 3 TOTP or PIN. 3 becomes 2 when the TOTP field is hidden. |
ShowWrongPasswordDialog | 1 | 1 shows a message when the stored credentials are wrong (for example after a password change). 0 turns it off. |
DoNotAllowMagicWords | 0 | 1 disables the keywords nfc, 2fa, changepwd and time in the logon fields (see keywords). Recommended for hardened PCs. |
Tile texts — Strings
String values under HKLM\SOFTWARE\CodeB\Strings replace the English texts on the tile, for example to translate them.
| Value | Default | Effect |
|---|---|---|
Username | Username | Label of the user name field. |
OptionalSecretOrPassword | Optional Secret or Password | Label of the password / optional secret field. |
TOTPorPIN | TOTP or PIN | Label of the TOTP / PIN field. |
ConfirmPassword | Confirm password | Label of the confirmation field (change-password screen). |
UnmaskFields | Display typed values | Label of the check box that shows typed values. |
CodeBLogon | Other User | Title of the extra tile. |
EnterYourCredentials | Enter your CodeB Credentials | Text shown on the selected tile. |
FailedCredentials | Please make sure that you present your token. | Message when no token or no matching credentials were found. |
Tokens & Active Directory — Config
| Value | Default | Effect |
|---|---|---|
DelayCardRemovalEventSEC | 10 | Seconds the provider waits after a card was lifted before it treats the card as removed, so a quick tap still completes the logon. 0 = no delay. Very long values usually hide another problem (reader driver, cold-boot timing). |
Use_AD_altSecurityIdentities | 1 | 1 looks up card links and tokens in the user’s AD attribute altSecurityIdentities. 0 uses only local or share data. |
ADAutoSync | 1 | For cards pre-enrolled for a “new user” in AD: 1 writes the card serial to the user’s AD object the first time the card is used; 0 only records it in the data folder (newuser\<user>.user). |
UseDomainDPAPI | 0 | 1 additionally protects new tokens with Windows DPAPI for the user and the domain computers, so only domain PCs can decrypt them. |
AutoUpdateADToken | 0 | 1 allows the CodeB helpers to update the password stored in the user’s AD soft token after a password change. |
RestartSmartCardServiceIfNoReaderDetected | 0 | 1 restarts the Windows Smart Card service when the logon tile finds no reader. Leave it off for Remote Desktop use. |
| Value (other key) | Default | Effect |
|---|---|---|
HKLM\SOFTWARE\Aloaha\CSP\DefaultSerialPIN | 0000 | PIN used for cards that were linked without a PIN (in the linking tools and in CodeBAdminCLI when /pin is omitted). Changing it affects the logon of all such cards. |
Removal actions — CP
What happens when a token is taken away while the user is logged on. The effective action is the highest of the global LogoffAction, the value of the token type and the action chosen when the token was linked.
| Value | Default | Effect |
|---|---|---|
CP\LogoffAction | 0 | Action for every token type when the token is removed: 0 nothing, 1 lock (disconnect in Remote Desktop), 2 log off. |
CP\CardToken\LogoffAction | 0 | Same for NFC cards and smartcards. |
CP\USBStick\LogoffAction | 0 | Same for USB memory sticks. |
CP\Bluetooth\LogoffAction | 0 | Same for Bluetooth tokens. |
CP\DoActionOnNoReader | 0 | 1 also runs the action when no card reader is present. |
CP\DoActionOnNoCard | 0 | 1 also runs the action when no card is in any reader. |
Subkeys such as CP\CardToken\<user> (values serial, Action, ts, SessionID) record the tokens of logged-on users. They are managed by the CodeB service — do not edit them.
Filter: hide other credential providers
The CodeB credential provider filter decides which other providers the logon screen shows. Hiding the Microsoft password tile with the filter is safer than disabling the Microsoft provider system-wide.
| Value | Default | Effect |
|---|---|---|
HKLM\SOFTWARE\Aloaha\CP\<provider CLSID> | 0 | 1 hides that credential provider. The value name is the provider’s CLSID without braces, for example Microsoft Password Provider 60b78e88-ead8-445c-9cfd-0b87f74ea6cd, Windows Hello PIN d6886603-9d2f-4eb2-b667-1971041fa96b. The same value under HKU\.DEFAULT\Software\Aloaha\CP is honoured too. |
HKLM\SOFTWARE\Aloaha\CP\AllowPasswordChange | 1 | 1 shows all providers on the Windows change-password screen; 0 filters there too. |
HKLM\SOFTWARE\Aloaha\CP\AllowPreLogonAccessProvider | 1 | 1 does not filter pre-logon access providers (for example VPN before logon); 0 filters them. |
Filter\ProcessExceptions\<process> | see text | 1: no filtering in credential prompts of that program (lower-case process name). Default 1 for credentialuibroker, consent (UAC) and systempropertiesadvanced, 0 for others. |
Filter\UserExceptions\<user> | 0 | 1: this user may log on on the CodeB tile with user name and password only, without a token (for example a service or emergency account). |
Before hiding the password provider, test token logon for every account that needs it and keep an emergency path (a UserExceptions account or remote registry access).
Automatic logon after boot
| Value | Default | Effect |
|---|---|---|
DefaultUserName | — | User for automatic logon. If empty, Windows’ own Winlogon\DefaultUserName is used. |
DefaultPassword | — | Password for automatic logon. If empty, Winlogon\DefaultPassword is used. |
Config\AutologonTimeout | 60 | Automatic logon happens only within this many seconds after Windows started (minimum 10). Later, for example after sign-out, the user has to log on normally. |
Automatic logon stores a password in the registry where administrators can read it. Use it only for kiosk or machine accounts.
Kerberos & authentication
| Value | Default | Effect |
|---|---|---|
CP\ForcedAuthPackage | 0 | Windows authentication package to use. 0 = automatic (recommended). |
CP\ForceKerberosUPN | none | Fixed UPN for certificate (Kerberos Connector) logon. none = off. |
CP\ForceKerberosDomain | none | Fixed domain for Kerberos logon. none = off. |
Config\CryptoProvider | CodeB Credential Provider | Name of the cryptographic service provider used by the Kerberos Connector. |
CP\TilePath | none | Full path of a bitmap shown as the tile picture. none = built-in picture. |
Folders & programs
| Value | Default | Effect |
|---|---|---|
DataFolder | C:\ProgramData\CodeB\ | Local folder for soft tokens and other data. Must be a full path. |
RemoteDataFolder | none | UNC path of a shared data folder (for example \\server\codeb\) used for tokens that must work on several PCs. |
2FAPath | — | Full path of Link2FA.exe, opened by the 2fa keyword. |
SystrayPath | — | Full path of the tray application; set by the installer. |
CP\AutoStart\Systray | 0 | 1: the CodeB service starts the tray application in every active user session. |
CP\AutoStart\Path | none | Program the CodeB service starts in every active user session. |
CP\AutoStart\PathParameter | none | Command-line parameters for that program. |
DataFolder and RemoteDataFolder are also accepted in the 64-bit view.
Tray application
| Value | Default | Effect |
|---|---|---|
Software\CodeB\Systray\enabled\onlinehelp | on | 0 or false removes Online help from the tray menu. |
Software\CodeB\Systray\enabled\joinmeeting | on | 0 or false removes Join meeting. |
Software\CodeB\Systray\enabled\about | on | 0 or false removes About. |
These values can be set in HKCU (per user) or HKLM (all users); a value in HKLM wins.
Debug logging
| Value | Default | Effect |
|---|---|---|
HKLM\SOFTWARE\Aloaha\pdf\debug | 0 | 1 writes detailed logs of the credential provider and its helpers to C:\Windows\Logs\CodeBProvider\. See Troubleshooting. Turn it off again afterwards. |
Example .reg file
A hardened NFC setup on 64-bit Windows: card PIN field focused, keywords off, lock on card removal, Microsoft password tile hidden.
Windows Registry Editor Version 5.00
; CodeB settings (32-bit view on 64-bit Windows)
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CodeB\Config]
"ActiveField"=dword:00000003
"DoNotAllowMagicWords"=dword:00000001
"HideExtraTile"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CodeB\CP\CardToken]
"LogoffAction"=dword:00000001
; filter (64-bit view): hide the Microsoft password tile
[HKEY_LOCAL_MACHINE\SOFTWARE\Aloaha\CP]
"60b78e88-ead8-445c-9cfd-0b87f74ea6cd"="1"
Frequently asked questions
Why can't I find HKLM\SOFTWARE\CodeB on a 64-bit PC?
The CodeB components read their settings from the 32-bit registry view. On 64-bit Windows look under HKLM\SOFTWARE\WOW6432Node\CodeB. Most values appear there automatically, with their default, the first time the logon screen reads them.
How do I hide the Microsoft password tile?
Set the string value HKLM\SOFTWARE\Aloaha\CP\60b78e88-ead8-445c-9cfd-0b87f74ea6cd to 1. The CodeB filter then hides the Microsoft Password Provider. Make sure every user can log on with a token first.
How do I make the card PIN field the focused field?
That is the default: ActiveField = 3 focuses the TOTP or PIN field. Use 2 for the password field and 1 for the user name.