"Domain controller: Allow vulnerable Netlogon secure channel connections" Group Policy

Jason Leidy 21 Reputation points
2020-09-10T23:06:42.097+00:00

I am trying to create a GPO to address the netlogon secure channel vulnerability, so that certain things won't be impacted in February. However, the instructions contained in the article "https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc" aren't working for me. I log onto my 2016 DC and open up Group Policy management. When I go to create the new GPO, per the instructions, I do not have Computer Configuration\Windows Settings\Security Settings\Security Options. Instead, I have Computer Configuration\Policies\Windows Settings\Security Settings

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Anonymous
    2020-09-14T20:02:56.797+00:00

    Check my earlier reply. From cmd.exe run gpedit.msc then navigate to;

    24631-image.png

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

12 additional answers

Sort by: Most helpful
  1. Chavdar Chavdarov 16 Reputation points
    2020-09-21T09:58:00.12+00:00

    Any advice how to find the missing setting!?
    I don't see this setting too. Its just missing -see attached screenshot

    26096-dcgpomissing.jpg

    Where you guys have 5 options starting with "Domain controller:..." I see 4, this option is MIA :/

    PS: The server in question is 2012R2 - could this be the reason?

    3 people found this answer helpful.

  2. Anonymous
    2020-09-11T01:45:48.543+00:00

    From cmd.exe run gpedit.msc then navigate to;

    24013-image.png

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  3. Anonymous
    2020-09-11T01:50:40.7+00:00

    Hi,

    Based on my understanding, you have already install the updates for your 2016 DC server,right?
    23934-9118.jpg

    download address: https://www.catalog.update.microsoft.com/Search.aspx?q=KB4571694

    When complete the updates, restart the DCs .
    Under the Computer Configuration > Windows Setting > Security Settings > Local Policy > Security Options,you can find the policy.
    23856-9117.jpg

    0 comments No comments

  4. Jason Leidy 21 Reputation points
    2020-09-14T18:52:28.717+00:00

    Hello, the update has been applied to all 2016 servers, including Domain Controllers. However, MS then says to configure the "Domain controller: Allow vulnerable Netlogon secure channel connections" Group Policy. They say this is done using GPMC and going to Computer Configuration > Windows Settings > Security Settings > Security Options. It isn't there. The path appears to be Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options. Sorry for not responding sooner but I am not getting email notifications when people reply to my posts. My settings are configured to get them.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.