Filter duplicate logon certificates
Verified with Windows 11 25H2 — updated on July 30, 2026
Supported on: At least Windows Vista
Path in the GPO console
Computer Configuration\Administrative Templates\Windows Components\Smart Card Description
This policy settings lets you configure if all your valid logon certificates are displayed. During the certificate renewal period, a user can have multiple valid logon certificates issued from the same certificate template. This can cause confusion as to which certificate to select for logon. The common case for this behavior is when a certificate is renewed and the old one has not yet expired. Two certificates are determined to be the same if they are issued from the same template with the same major version and they are for the same user (determined by their UPN). If there are two or more of the "same" certificate on a smart card and this policy is enabled then the certificate that is used for logon on Windows 2000, Windows XP, and Windows 2003 Server will be shown, otherwise the the certificate with the expiration time furthest in the future will be shown. Note: This setting will be applied after the following policy: "Allow time invalid certificates" If you enable or do not configure this policy setting, filtering will take place. If you disable this policy setting, no filtering will take place.
Registry
SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider Value name: FilterDuplicateCerts
Enabled: FilterDuplicateCerts = 1
Disabled: FilterDuplicateCerts = 0
MDM / Intune (CSP)
./Device/Vendor/MSFT/Policy/Config/ADMX_Smartcard/FilterDuplicateCerts Microsoft Learn documentation Mapping data: Microsoft Learn (CC BY 4.0)
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Filter duplicate logon certificates
; State: Enabled
; Supported on: At least Windows Vista
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider]
"FilterDuplicateCerts"=dword:00000001 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Filter duplicate logon certificates
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'FilterDuplicateCerts' -Value 1 -Type DWord Intune XML
OMA-URI: ./Device/Vendor/MSFT/Policy/Config/ADMX_Smartcard/FilterDuplicateCerts
Data type: String
Value:
<enabled/> Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Filter duplicate logon certificates
# State: Enabled
# Supported on: At least Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider' -Name 'FilterDuplicateCerts' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Filter duplicate logon certificates
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'FilterDuplicateCerts' -Value 1 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Filter duplicate logon certificates
# State: Enabled
# Supported on: At least Windows Vista
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Filter duplicate logon certificates
# State: Enabled
# Supported on: At least Windows Vista
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider' -Name 'FilterDuplicateCerts' -Expected 1 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Filter duplicate logon certificates
# State: Enabled
# Supported on: At least Windows Vista
$path = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\SmartCardCredentialProvider'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'FilterDuplicateCerts' -Value 1 -Type DWord Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.