Which version of NTLM is logged with the NTLM Audit GPO's?

p0shkar 26 Reputation points
2024-01-03T14:37:10.5033333+00:00

Does anyone know if the following two GPO's log only NTLM (v1) or both v1 and v2? Or do we have to enable "Logon Success Auditing" to figure that out?

Network security: Restrict NTLM: Audit NTLM authentication in this domain

Network security: Restrict NTLM: Audit incoming NTLM traffic

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | User experience | Other
Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2024-01-04T04:51:39.04+00:00

    Hi p0shkar,

    These Restrict NTLM GPOs will audit both NTLM and NTLM v2 traffic.

    Best Regards,

    Ian Xue


    If the Answer is helpful, please click "Accept Answer" and upvote it.

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Thameur-BOURBITA 36,266 Reputation points Moderator
    2024-01-03T16:48:54.6533333+00:00

    Hi @p0shkar

    Network security: Restrict NTLM: Audit NTLM authentication in this domain
    Network security: Restrict NTLM: Audit incoming NTLM traffic
    => these seetings should be enough to enable NTLMv1 audit and identify the server still using this protocol by checking the event 4624.

    You can also enable "Logon Success Auditing if you want get more details but it's not required.

    I invite you to read the following link for more details:

    Auditing and restricting NTLM authentication using Group Policy


    Please don't forget to accept helpful answer

    0 comments No comments

  2. p0shkar 26 Reputation points
    2024-01-04T11:00:57.15+00:00

    Thanks both for the answers!

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.