Enforce the use of NTLMv2

Andreas 1,321 Reputation points
2022-09-27T18:28:40.727+00:00

Hi,

If I want to enforce the use of NTLMv2 with the below GPO settings do I have to apply this to both the domain controller and the clients ?
It seems like if I only apply this to the client then when I reboot the client I get the warning below.
Or..... If I only apply this to the domain controllers will that force all the clients to use NTLMv2 when they authenticate with the domain controller ?

245203-ntlmv1.png

245241-ntlm.png

Thanks for any reply

/R
Andy

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,578 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,843 questions
0 comments No comments
{count} votes

Accepted answer
  1. Scott Dawson 156 Reputation points
    2022-09-28T04:39:20.71+00:00

    Yes you have to apply to DC's, clients, servers, all objects basically. This is the internal server setting. So the GPO that applies to clients is for the client receiving NTLM requests, how the client handles them. The GPO on DCs is for the DC receiving NTLM requests, how the DC handles them..

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Anonymous
    2022-09-27T18:38:34.527+00:00
    1 person found this answer helpful.
    0 comments No comments

  2. Andreas 1,321 Reputation points
    2022-09-28T04:29:56.12+00:00

    Hi,

    Thanks for the reply, but not the answer I was looking for I belive.

    The link you refer to is "Network Security: Restrict NTLM: NTLM authentication in this domain", and since I want to only use NTLMv2 It would be enough to configure "Network security: LAN Manager authentication level - Send NTLMv2 responses only. Refuse LM & NTLM", am I not wrong ?

    If I don't understand correctly, the link you provide is an exception, so that I can list some computers to be allowed with NTLM?

    But again, my question is "If I want to enforce the use of NTLMv2 with the below GPO settings do I have to apply this to both the domain controller and the clients ? Or I might not understand this correctly so please explain :)

    Thanks again for answers.

    /R
    Andy

    0 comments No comments

  3. Andreas 1,321 Reputation points
    2022-09-28T10:44:31.99+00:00

    Hi,

    Thanks for reply @Scott Dawson
    If I deploy it to the domain controller, then I guess all clients will be affected right away ? I would like to implement this in segments, say 50 and 50 machines, but I guess that would not work since I have to deploy it on the domain controllers for the system to work ? Right ?
    I know I can implement logging, So I guess I would have to do that first.....

    comments ?

    /R
    Andy


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.