ZEROLOGON - GPO - Active Directory

Mike OConnor 31 Reputation points
2020-09-29T15:37:25.287+00:00

Hi there Microsoft!

I have an AD Domain running 2 x 2016 Domain Controllers (virtual) - FFL & DFL are both 2012R2 and were uplifted recently from 2008R2.

The single domain in a single forest has recently been uplifted from 2008R2, the old 2008r2 DCs were retired gracefully using DCPROMO.

Schema version is 87.

The 2016 DCs are both patched fully up to date too and the following reg key is present indicating that the patches have been applied successfully:-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters]
"FullSecureChannelProtection"=dword:00000000

My question is this:-

In the Group Policy Console, within a brand new GPO - this configuration item is missing:-

"Domain Controller: Allow vulnerable Netlogon secure channel connections"

I can confirm that all ADMX Files are up to date.

Any help would be fantastic - i need to set some exceptions using this GPO before i can fix the ZEROLOGON issue.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,002 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,154 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,775 questions
0 comments No comments
{count} votes

8 additional answers

Sort by: Most helpful
  1. Mike OConnor 31 Reputation points
    2020-10-02T12:35:51.097+00:00

    Hi guys - these has now been resolved for me - so thanks for the help.

    Theres a good learning point here which has only become apparent through this exercise:-

    As mentioned in the OP - The forest in question for 2008r2 and has been uplifted to FFL 2012R2. At the start of the uplift - all DCs were fully patched.

    KB4577015 is a red herring and just complicated the situation - remove it if you have to until Microsoft resolve the issue.

    KB4571694 need to be installed manually on both 2016 DCs in order to reveal the - "Domain Controller: Allow vulnerable Netlogon secure channel connections" configuration item

    I think that KB4571694 wasnt showing as being needed in WSUS because there were 2008R2 Domain Controllers kicking around. Even after the 2008R2 boxes were demoted, and the FFL & DFL raised - the DCs still wouldnt pick this up in WSUS.

    Anyways - all is good now. So thank you very much.

    Mike

    2 people found this answer helpful.
    0 comments No comments

  2. Dave Patrick 426.4K Reputation points MVP
    2020-09-29T18:00:25.507+00:00

    I'd look for it in local security policy gpedit.msc Also note if you have installed the September 8, 2020—KB4577015 then this dialog was broken by the update.

    29169-image.png

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  3. Mike OConnor 31 Reputation points
    2020-09-30T11:41:43.857+00:00

    Hiya,

    Local and Domain group policy editors both crash the MMC when trying to access that function since the Sep20 patch went on.

    I have built a spare 2012r2 server to access the Domain GP Console which works fine - BUT the features within the GPO are still missing and im not sure how to enable them.

    Any ideas?

    0 comments No comments

  4. Dave Patrick 426.4K Reputation points MVP
    2020-09-30T12:17:22.07+00:00

    I'd look for it in local security policy gpedit.msc As mentioned if you have installed the September 8, 2020—KB4577015 then this dialog was broken by the update so for now the only option is to uninstall KB4577015.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments