Final check before Fully Block NTLM for all Domain

Namless Shelter 231 Reputation points
2024-05-02T04:25:22.4766667+00:00

Dear PPL,

I would like to set our Default Domain Policy "Restrict NTLM: Incoming NTLM Traffic" to Deny All Accounts.

Before I do it, I have enabled Auditing Logs, can see some devices or services are still using NTLM, for example, Win10 devices, Palo UserID Agent, some LDAP queries from OP Manager etc..

My concern now is: there is no way disabling NTLM will break:

Microsoft HyperV Failover Cluster, DFS or User Based 802.1x Wifi etc?

Also, how can add third party servers or services to be exclusion to still be able to use NTLMv2? I dont see a way to add IP address?

Thanks a lot,

Larry

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,503 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,772 questions
0 comments No comments
{count} votes