Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
BlockAll
| Scope | Editions | Applicable OS |
|---|---|---|
| ✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 11, version 24H2 [10.0.26100] and later |
./Device/Vendor/MSFT/Policy/Config/NTLM/BlockAll
This policy blocks all outbound NTLM authentication regardless of account type or target. Any target not in the EnhancedMachineBlockingAllowList will be blocked. This is the most restrictive policy; when enabled it takes effect even if no other blocking policies are configured. 0=Disabled, 1=Audit, 2=Enabled.
Description framework properties:
| Property name | Property value |
|---|---|
| Format | int |
| Access Type | Add, Delete, Get, Replace |
| Default Value | 0 |
Allowed values:
| Value | Description |
|---|---|
| 0 (Default) | Disabled. |
| 1 | Audit. |
| 2 | Enabled. |
BlockDomainAccountSSO
| Scope | Editions | Applicable OS |
|---|---|---|
| ✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 11, version 24H2 [10.0.26100] and later |
./Device/Vendor/MSFT/Policy/Config/NTLM/BlockDomainAccountSSO
This policy controls whether outbound NTLM Single Sign-On is blocked for domain accounts (OnPrem or hybrid) during interactive logon sessions (console, RDP, Unlock, runas /netonly). When enabled, the machine won't use NTLM for SSO on behalf of interactively logged-on domain accounts. Supplied-credential flows are unaffected. Targets in the EnhancedMachineBlockingAllowList with the [ForDomainSso] tag are exempt. 0=Disabled, 1=Audit, 2=Enabled.
Description framework properties:
| Property name | Property value |
|---|---|
| Format | int |
| Access Type | Add, Delete, Get, Replace |
| Default Value | 0 |
Allowed values:
| Value | Description |
|---|---|
| 0 (Default) | Disabled. |
| 1 | Audit. |
| 2 | Enabled. |
EnforceMachineBinding
| Scope | Editions | Applicable OS |
|---|---|---|
| ✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 11, version 24H2 [10.0.26100] and later |
./Device/Vendor/MSFT/Policy/Config/NTLM/EnforceMachineBinding
This policy validates that the host portion of the client-supplied SPN matches the NetBIOS or DNS name reported by the NTLM server. If they match, NTLM is allowed; if not, it's blocked. Targets in the EnhancedMachineBlockingAllowList with the [ForMachineBinding] tag are exempt. 0=Disabled, 1=Audit, 2=Enabled.
Description framework properties:
| Property name | Property value |
|---|---|
| Format | int |
| Access Type | Add, Delete, Get, Replace |
| Default Value | 0 |
Allowed values:
| Value | Description |
|---|---|
| 0 (Default) | Disabled. |
| 1 | Audit. |
| 2 | Enabled. |
EnhancedMachineBlockingAllowList
| Scope | Editions | Applicable OS |
|---|---|---|
| ✅ Device ❌ User |
✅ Pro ✅ Enterprise ✅ Education ✅ IoT Enterprise / IoT Enterprise LTSC |
✅ Windows 11, version 24H2 [10.0.26100] and later |
./Device/Vendor/MSFT/Policy/Config/NTLM/EnhancedMachineBlockingAllowList
This policy specifies a REG_MULTI_SZ allow-list of SPN entries that are exempt from NTLM blocking policies. Each entry uses the format [Tag1,Tag2]SPN where optional tags scope the exemption: ForDcAuth (exempts from BlockDomainControllerAuth), ForDomainSso (exempts from BlockDomainAccountSSO), ForMachineBinding (exempts from EnforceMachineBinding). An entry with no tags is exempt from all policies. Tags are case-insensitive. Wildcards are supported. Example: [ForDcAuth]cifs/dc.contoso.com.
Description framework properties:
| Property name | Property value |
|---|---|
| Format | chr (string) |
| Access Type | Add, Delete, Get, Replace |
| Allowed Values | List (Delimiter: 0xF000) |