How does one disable NTLM in Windows Server 2019?

techcoor 1,251 Reputation points
2021-05-14T18:18:31.167+00:00

dcdiag gives:

Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.

        NTLM is a weaker authentication mechanism. Please check:  

           

              Which applications are using NTLM authentication?  

              Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?  

              If NTLM must be supported, is Extended Protection configured?  

           

        Details on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.  

If I look up how to disable online I get something that looks like

96758-image.png
https://techdirectarchive.com/2020/04/01/how-to-prevent-ntlm-credentials-from-being-sent-to-remote-servers-2/

I do not see the same settings in Windows Server 2019.

96802-image.png

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,561 questions
0 comments No comments
{count} votes

1 additional answer

Sort by: Most helpful
  1. techcoor 1,251 Reputation points
    2021-05-14T22:51:34.017+00:00

    If I use your link, Microsoft Edge will block. I will substitute Your link

    Your link gives wrong location. You
    Your link says “Open the Group Policy Management Editor (gpmc.msc) and edit the Default Domain Policy.” The correct location is Default Domain Controllers Policy.

    The way I reached the location is by Forest, Domains, domain name, Group Policy Objects. Right click Default Domain Controllers Policy and select edit. Now I can go select Computer Configuration, Policies, Windows Settings, Security Settings, Local Policies, Security Options as shown in Your link Then I can set LAN Manager authentication level to Send NTLMv2 response only. Refuse LM & NTLM as well as the other settings listed

    0 comments No comments