Jump to content

Recommended Posts

Posted (edited)

A while ago I decided I would take the plunge and enable the following for my DCs:

 

Network security: Restrict NTLM: NTLM authentication in this domain - Deny all

 

I had enabled the AUDIT version of this policy for a while beforehand and it only seemed to pick up the Head's MacBook... so I thought it would be worth doing and then seeing if it broke anything (he uses the Microsoft Remote Desktop app for Mac to connect to a VM on the server for SIMS) as I figured I could reverse it if it did.

 

However, following recent updates I had to reboot the servers and among the event viewer logs I found this:

 

Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. This event occurs once per boot of the server on the first time a client uses NTLM with this server.

 

NTLM is a weaker authentication mechanism. Please check:

 

Which applications are using NTLM authentication?

Are there configuration issues preventing the use of stronger authentication such as Kerberos authentication?

If NTLM must be supported, is Extended Protection configured?

 

Details on how to complete these checks can be found at http://go.microsoft.com/fwlink/?LinkId=225699.

 

The link basically tells you to use the AUDIT mode first...

 

Also, I will occasionally get the following:

 

Domain Controller Blocked: NTLM authentication to this domain controller is blocked.

Secure Channel name: LAPTOP-1

User name: USER-1

Domain name: DOMAIN

Workstation name: LAPTOP-1

Secure Channel type: 2

 

NTLM authentication within the domain DOMAIN is blocked.

 

In the Details tab:

 

- System

 

- Provider

 

[ Name] Microsoft-Windows-Security-Netlogon

[ Guid] {E5BA83F6-07D0-46B1-8BC7-7E669A1D31DC}

 

EventID 4004

 

Version 0

 

Level 3

 

Task 1

 

Opcode 0

 

Keywords 0x8000000000000000

 

- TimeCreated

 

[ SystemTime] 2021-11-08T08:15:48.412185900Z

 

EventRecordID 24987

 

Correlation

 

- Execution

 

[ ProcessID] 712

[ ThreadID] 59704

 

Channel Microsoft-Windows-NTLM/Operational

 

Computer DC.Domain.com

 

- Security

 

[ UserID] S-1-5-18

 

 

- EventData

 

SChannelName LAPTOP-1

UserName USER-1

DomainName DOMAIN

WorkstationName LAPTOP-1

SChannelType 2

 

 

But I can't really figure out from this what is using NTLM and why (is it attempting a log-on with NTLM and failing - then going Kerberos)..? Nothing appears to be broken within the Domain, all printing (before the Nightmare) and shares work OK.

 

Occasionally other laptops will pop up, but I've never been informed that this is causing problems (not that it isn't, just that I haven't been informed).

 

I will also say that during my 'Print Nightmare' testing the occurrences of this go through the roof!

 

But mainly the question is whether I have successfully blocked NTLM or not, as the GPO seems to produce event logs saying it is blocked, but the reboot event log says NTLM is currently being used...

 

The only thing I can think of (and have just noticed) is that I still have the AUDIT policy enforced, but would that prevent the 'proper' GPO from applying...?

Edited by Koldov

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...