Controls local security authority, Kerberos, and NTLM parameters for network authentication and encryption policies on Windows.
Fields
| Field Name | Description |
|---|---|
enableMdns - Boolean
|
Whether the DNS client performs name resolution over multicast DNS (mDNS). |
restrictSendingNTLMTraffic - OutgoingNTLMTrafficRestriction
|
Restriction applied to outgoing NTLM traffic to remote servers. See OutgoingNTLMTrafficRestriction. |
auditReceivingNTLMTraffic - IncomingNTLMTrafficAuditing
|
Auditing of incoming NTLM traffic. See IncomingNTLMTrafficAuditing. |
lDAPClientConfidentiality - ClientEncryptionRequirement
|
LDAP client encryption (sealing) requirements. See ClientEncryptionRequirement. |
useMachineId - Boolean
|
Allow Local System to use computer identity for NTLM authentication. |
allowNullSessionFallBack - Boolean
|
Allow LocalSystem NULL session fallback. |
allowOnlineID - Boolean
|
Allow PKU2U authentication requests to this computer to use online identities. |
supportedEncryptionTypes - [KerberosEncryptionType!]
|
Encryption types allowed for Kerberos. |
noLMHash - Boolean
|
Prevent storage of LAN Manager hash values for local passwords. |
lmCompatibilityLevel - LanManagerAuthLevel
|
LAN Manager authentication level. |
lDAPClientIntegrity - ClientSigningRequirement
|
LDAP client signing requirements. |
nTLMMinClientSec - [SessionSecurity!]
|
Minimum NTLM session security for client connections. |
nTLMMinServerSec - [SessionSecurity!]
|
Minimum NTLM session security for server connections. |
Used by
LocalPoliciesWindowstype: Windows-specific local security and system policies.
Example
Example
{
"enableMdns": false,
"restrictSendingNTLMTraffic": "ALLOW_ALL",
"auditReceivingNTLMTraffic": "DISABLED",
"lDAPClientConfidentiality": "NONE",
"useMachineId": true,
"allowNullSessionFallBack": true,
"allowOnlineID": true,
"supportedEncryptionTypes": ["DES_CBC_CRC"],
"noLMHash": false,
"lmCompatibilityLevel": "SEND_LM_NTLM_RESPONSE",
"lDAPClientIntegrity": "NEGOTIATE_SIGNING",
"nTLMMinClientSec": ["REQUIRE_NTLMV2_SESSION_SECURITY"],
"nTLMMinServerSec": ["REQUIRE_NTLMV2_SESSION_SECURITY"]
}