Policy CSP - NTLM

BlockAll

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 11, version 24H2 [10.0.26100] and later
./Device/Vendor/MSFT/Policy/Config/NTLM/BlockAll

This policy blocks all outbound NTLM authentication regardless of account type or target. Any target not in the EnhancedMachineBlockingAllowList will be blocked. This is the most restrictive policy; when enabled it takes effect even if no other blocking policies are configured. 0=Disabled, 1=Audit, 2=Enabled.

Description framework properties:

Property name Property value
Format int
Access Type Add, Delete, Get, Replace
Default Value 0

Allowed values:

Value Description
0 (Default) Disabled.
1 Audit.
2 Enabled.

BlockDomainAccountSSO

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 11, version 24H2 [10.0.26100] and later
./Device/Vendor/MSFT/Policy/Config/NTLM/BlockDomainAccountSSO

This policy controls whether outbound NTLM Single Sign-On is blocked for domain accounts (OnPrem or hybrid) during interactive logon sessions (console, RDP, Unlock, runas /netonly). When enabled, the machine won't use NTLM for SSO on behalf of interactively logged-on domain accounts. Supplied-credential flows are unaffected. Targets in the EnhancedMachineBlockingAllowList with the [ForDomainSso] tag are exempt. 0=Disabled, 1=Audit, 2=Enabled.

Description framework properties:

Property name Property value
Format int
Access Type Add, Delete, Get, Replace
Default Value 0

Allowed values:

Value Description
0 (Default) Disabled.
1 Audit.
2 Enabled.

EnforceMachineBinding

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 11, version 24H2 [10.0.26100] and later
./Device/Vendor/MSFT/Policy/Config/NTLM/EnforceMachineBinding

This policy validates that the host portion of the client-supplied SPN matches the NetBIOS or DNS name reported by the NTLM server. If they match, NTLM is allowed; if not, it's blocked. Targets in the EnhancedMachineBlockingAllowList with the [ForMachineBinding] tag are exempt. 0=Disabled, 1=Audit, 2=Enabled.

Description framework properties:

Property name Property value
Format int
Access Type Add, Delete, Get, Replace
Default Value 0

Allowed values:

Value Description
0 (Default) Disabled.
1 Audit.
2 Enabled.

EnhancedMachineBlockingAllowList

Scope Editions Applicable OS
✅ Device
❌ User
✅ Pro
✅ Enterprise
✅ Education
✅ IoT Enterprise / IoT Enterprise LTSC
✅ Windows 11, version 24H2 [10.0.26100] and later
./Device/Vendor/MSFT/Policy/Config/NTLM/EnhancedMachineBlockingAllowList

This policy specifies a REG_MULTI_SZ allow-list of SPN entries that are exempt from NTLM blocking policies. Each entry uses the format [Tag1,Tag2]SPN where optional tags scope the exemption: ForDcAuth (exempts from BlockDomainControllerAuth), ForDomainSso (exempts from BlockDomainAccountSSO), ForMachineBinding (exempts from EnforceMachineBinding). An entry with no tags is exempt from all policies. Tags are case-insensitive. Wildcards are supported. Example: [ForDcAuth]cifs/dc.contoso.com.

Description framework properties:

Property name Property value
Format chr (string)
Access Type Add, Delete, Get, Replace
Allowed Values List (Delimiter: 0xF000)

Policy configuration service provider