Pricing  Get Quote
 
 
 

What is Network security: Restrict NTLM: Incoming NTLM traffic policy setting?

Network security: Restrict NTLM: Incoming NTLM traffic is a security policy setting, that when enabled, will block all the incoming NTLM requests from client computers, member servers and domain controllers.

There are two ways of enabling this policy:

  • Deny all domain accounts: Selecting this option means thata all the domain accounts that attempt to logon with NTLM will be denied their request. But local accounts will be allowed to logon.
  • Deny all accounts: If this option is enabled, all accounts (Domain accounts and local accounts) will be blocked from logging in.

Disabling this policy means that all accounts will be allowed to logon using NTLM authentication.

Recommended Practices:

You need to evaluate the level of threat your organization faces and balance it against the cost of your time and effort in resetting the password. This decisions is organizations dependent. However, the Microsoft recommend setting the Reset account lockout counter after policy setting to 15.

Security Implications and combative measures:

There are some security issues to consider about this policy setting's configuration. If the value is set to a long interval a malicious entity could make repeated attempts to log into a user's account and lock out their accounts, resulting in a denial-of-service (DoS) attack. This leads to administrators having to reset accounts for compromised users in an organization. If you configure this policy setting to a reasonable value you can block high speed brute force attacks and provide enough number of chances for users who mistype their passwords. Ensure you notify users of the number of login attempts that they're allowed and for how long they should wait for the lockout timer to expire before they inform the IT administrator.

About ADAudit Plus

ADAudit Plus is a real time change auditing software that helps keep your Active Directory, Azure AD, Windows file servers, NetApp filers, EMC file systems, Synology file systems, Windows member servers, and workstations secure and compliant. With ADAudit Plus, you can get visibility into:

among other things.

There are more than 200 event-specific reports, and you can configure instant email alerts. You can also export the reports to XLS, HTML, PDF and CSV formats to assist in interpretation and forensics.

Audit and monitor Windows security policy settings in real time with ADAudit Plus.

Download Now