ZEROLOGON - GPO - Active Directory

Mike OConnor 31 Reputation points
2020-09-29T15:37:25.287+00:00

Hi there Microsoft!

I have an AD Domain running 2 x 2016 Domain Controllers (virtual) - FFL & DFL are both 2012R2 and were uplifted recently from 2008R2.

The single domain in a single forest has recently been uplifted from 2008R2, the old 2008r2 DCs were retired gracefully using DCPROMO.

Schema version is 87.

The 2016 DCs are both patched fully up to date too and the following reg key is present indicating that the patches have been applied successfully:-

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters]
"FullSecureChannelProtection"=dword:00000000

My question is this:-

In the Group Policy Console, within a brand new GPO - this configuration item is missing:-

"Domain Controller: Allow vulnerable Netlogon secure channel connections"

I can confirm that all ADMX Files are up to date.

Any help would be fantastic - i need to set some exceptions using this GPO before i can fix the ZEROLOGON issue.

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
5,384 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,524 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,834 questions
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2020-09-30T19:07:48.073+00:00

    I'd check that this one has been installed.
    August 11, 2020—KB4571694 (OS Build 14393.3866)
    https://www.catalog.update.microsoft.com/Search.aspx?q=KB4571694

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

8 additional answers

Sort by: Most helpful
  1. Mike OConnor 31 Reputation points
    2020-09-30T19:03:49.653+00:00

    Ok - i have removed the offending KB and have rebooted. I can now access that particular portion of the mmc without it crashing.

    BUT

    When looking at either the local group policy console, or the domain one - i still cant see this missing configuration item:-

    "Domain Controller: Allow vulnerable Netlogon secure channel connections"

    Any ideas?

    0 comments No comments

  2. ChrisDz 26 Reputation points
    2020-10-02T07:22:08.997+00:00

    Hello,
    I have the same issue :
    "Domain Controller: Allow vulnerable Netlogon secure channel connections" is missing !!

    Is it possible that the patched server wasn't PDC emulator, and that another DC server overwrite policydefinitions folder with older admx files (in patched server 's SYSVOL) during FRS replication ?

    thanks

    0 comments No comments

  3. Anonymous
    2020-10-02T12:37:52.84+00:00

    Glad to hear, you're welcome.

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  4. ChrisDz 26 Reputation points
    2020-10-05T14:35:28.86+00:00

    thanks for your answer !!

    KB4571694 need to be installed manually on both 2016 DCs in order to reveal the - "Domain Controller: Allow vulnerable Netlogon secure channel connections" configuration item

    What is the mechanism behind that ? just by curiosity

    regards

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.