NTLM authentication level 5, cant login in domain

RAN55 176 Reputation points
2024-10-07T10:05:59.54+00:00

Hello,

Domain Controllers > Windows server 2019

Clients > Windows server 2019 and Windows 10 22H2

I have set this option on domain controller policy

111

After that I have not been able to log in again via rdp with my domain account, it was blocked on the first attempt.

I have not been able to log in either from a server member.

I had to log in with the domain administrator and change the gpo again.

Why is this happening? shouldn't I be able to log in with kerberos validation without problems?

Best regards,

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,932 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 32,416 Reputation points Microsoft External Staff
    2024-10-07T14:40:12.2033333+00:00

    Hello RAN55,

    Thank you for posting in Q&A forum.

    Based on the description, you set the fifth option, it means the domain controller only accepts the NTLMv2 protocol.

    Which one did you set on Windows server 2019 and Windows 10 22H2?

    On clients->Windows server 2019 and Windows 10 22H2, you should set 3 or 4 or 5 (below).

    User's image

    Reference:

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.