GPO policy: "Network security: Restrict NTLM: Audit Incoming NTLM Traffic" under Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options. Registry: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0:AuditReceivingNTLMTraffic (REG_DWORD). Reference: Network security: Restrict NTLM: Audit incoming NTLM traffic
Values
| Enum Value | Description |
|---|---|
|
|
Incoming NTLM traffic is not audited. |
|
|
Audit incoming NTLM pass-through authentication for domain accounts. |
|
|
Audit incoming NTLM traffic for all accounts. |
Used by
NetworkSecurityPolicytype: Controls local security authority, Kerberos, and NTLM parameters for network authentication and encryption policies on Windows.
Example
Example
"DISABLED"