Disable use of NTLMv1

Andreas 1,321 Reputation points
2023-02-16T06:41:10.2133333+00:00

Hi,

We are doing some testing on disabling the use of NTLMv1. (we have also implemented logging for a while), I have configured a GPO with the following settings: Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Network security: LAN Manager authentication level = 5

I have deployed this GPO to one Windows Server 2019 server, and from the local policy I can see that it has been applied.

User's image

If I login to another server then, and try to map a share with IP (\10.0.0.1\c$) it gives me the error below in the event log, and the mapping works. I thought it would fail because when using IP instead of FQDN it uses NTLM. (If I add the user to protected user group, then the mapping fails since NTLM then is disabled by the user group)

User's image

So my question is, do I have to assign this GPO also to the domain controller that the server authenticate against ? I hope not since I want to implement this carefully, and was hoping to take one server at the time, and then when all servers and clients are configured I could then configure the domain controllers.

Thanks for any reply

/R

Andy

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,388 questions
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,068 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,531 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,836 questions
0 comments No comments
{count} votes

Accepted answer
  1. Thameur-BOURBITA 32,981 Reputation points
    2023-02-16T14:22:19.2166667+00:00

    Hi @Andreas

    Before disabling NTLMv1, you should identify the services and machines that they still use it.

    You can monitor from the event viewer of all DCs, where you can check if there are connection attempts with ntlmv1.

    You can start with the servers first then the client machines. In other hand , I recommend you to disable it on the servers and client workstations gradually in order to be able to control incidents generated after the deactivation of ntlmv1 and not to exceed the capacity of the support team.

    For domain controllers, I also recommend that you proceed gradually, even if NTLMv1 is disabled on all servers and client workstations, it is possible to have applications (non-microsoft)or equipment that authenticates via ntlmv1.

    Please don't forget to mark helpful answer as accepted

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.