"Domain controller: Allow vulnerable Netlogon secure channel connections" Group Policy

Jason Leidy 21 Reputation points
2020-09-10T23:06:42.097+00:00

I am trying to create a GPO to address the netlogon secure channel vulnerability, so that certain things won't be impacted in February. However, the instructions contained in the article "https://support.microsoft.com/en-us/help/4557222/how-to-manage-the-changes-in-netlogon-secure-channel-connections-assoc" aren't working for me. I log onto my 2016 DC and open up Group Policy management. When I go to create the new GPO, per the instructions, I do not have Computer Configuration\Windows Settings\Security Settings\Security Options. Instead, I have Computer Configuration\Policies\Windows Settings\Security Settings

Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Anonymous
    2020-09-14T20:02:56.797+00:00

    Check my earlier reply. From cmd.exe run gpedit.msc then navigate to;

    24631-image.png

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

12 additional answers

Sort by: Most helpful
  1. JPB 1 Reputation point
    2020-09-23T19:28:14.25+00:00

    FYI,

    I found that I only see the option when I RDP into one of the DC's and look with GPMC there. If I use an admin server with the tools installed and check remotely I do not see the setting.

    Thanks,
    JPB

    0 comments No comments

  2. Daniel Camilo Quinchanegua Pulido 1 Reputation point
    2020-09-30T21:23:08.687+00:00

    Hi everyone,
    In my case I updated my domain controller (Windows Server 2016) with 2020-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4571694). The same thing happens to me as several of you, it is installed and appears in the installed updates, but when I look in the group policy management console, I cannot find the option "Domain controller: Allow vulnerable Netlogon secure channel connections". I have already restarted the server but that setting still does not appear in the GPO, does anyone know what this depends on in order to have the option to add exceptions while identifying vulnerable cases when they arise?

    Best regards,
    Daniel.


  3. ChrisDz 26 Reputation points
    2020-10-01T09:44:45.38+00:00

    is it possible that another domain controller overwrite the sysvol folder of my patched domain controller during sysvol frs synchronization/replication ?
    and it overwrites with older admx files ?
    thanks

    0 comments No comments

  4. INTREPID 41 Reputation points
    2020-11-01T17:14:49.443+00:00

    POSSIBLE BUG: On Server 2012 R2, When the Policy "Domain controller: Allow vulnerable Netlogon secure channel connections" is set to NOT DEFINED, this registry key STILL contains old PREVIOUSLY set entries (security descriptors) in the list!!!!
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters]
    "vulnerablechannelallowlist"

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.