---
title: NetworkSecurityPolicy type | Wartiva GraphQL API
description: Controls local security authority, Kerberos, and NTLM parameters for network authentication and encryption policies on Windows.
url: https://wartiva.com/api-docs/types/network-security-policy.html
updated: 2026-10-07
---

Endpoint configuration · GraphQL type

# `NetworkSecurityPolicy` type

Controls local security authority, Kerberos, and NTLM parameters for network authentication and encryption policies on Windows.

## Fields

| Field Name | Description |
|---|---|
| `enableMdns` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) | Whether the DNS client performs name resolution over multicast DNS (mDNS). |
| `restrictSendingNTLMTraffic` - [`OutgoingNTLMTrafficRestriction`](https://wartiva.com/api-docs/types/outgoing-ntlm-traffic-restriction.html) | Restriction applied to outgoing NTLM traffic to remote servers. See [OutgoingNTLMTrafficRestriction](https://wartiva.com/api-docs/types/outgoing-ntlm-traffic-restriction.html). |
| `auditReceivingNTLMTraffic` - [`IncomingNTLMTrafficAuditing`](https://wartiva.com/api-docs/types/incoming-ntlm-traffic-auditing.html) | Auditing of incoming NTLM traffic. See [IncomingNTLMTrafficAuditing](https://wartiva.com/api-docs/types/incoming-ntlm-traffic-auditing.html). |
| `lDAPClientConfidentiality` - [`ClientEncryptionRequirement`](https://wartiva.com/api-docs/types/client-encryption-requirement.html) | LDAP client encryption (sealing) requirements. See [ClientEncryptionRequirement](https://wartiva.com/api-docs/types/client-encryption-requirement.html). |
| `useMachineId` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) | Allow Local System to use computer identity for NTLM authentication. |
| `allowNullSessionFallBack` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) | Allow LocalSystem NULL session fallback. |
| `allowOnlineID` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) | Allow PKU2U authentication requests to this computer to use online identities. |
| `supportedEncryptionTypes` - [`[KerberosEncryptionType!]`](https://wartiva.com/api-docs/types/kerberos-encryption-type.html) | Encryption types allowed for Kerberos. |
| `noLMHash` - [`Boolean`](https://wartiva.com/api-docs/types/boolean.html) | Prevent storage of LAN Manager hash values for local passwords. |
| `lmCompatibilityLevel` - [`LanManagerAuthLevel`](https://wartiva.com/api-docs/types/lan-manager-auth-level.html) | LAN Manager authentication level. |
| `lDAPClientIntegrity` - [`ClientSigningRequirement`](https://wartiva.com/api-docs/types/client-signing-requirement.html) | LDAP client signing requirements. |
| `nTLMMinClientSec` - [`[SessionSecurity!]`](https://wartiva.com/api-docs/types/session-security.html) | Minimum NTLM session security for client connections. |
| `nTLMMinServerSec` - [`[SessionSecurity!]`](https://wartiva.com/api-docs/types/session-security.html) | Minimum NTLM session security for server connections. |

## Used by

- [`LocalPoliciesWindows`](https://wartiva.com/api-docs/types/local-policies-windows.html) type: Windows-specific local security and system policies.

## Example

### Example

```json
{
  "enableMdns": false,
  "restrictSendingNTLMTraffic": "ALLOW_ALL",
  "auditReceivingNTLMTraffic": "DISABLED",
  "lDAPClientConfidentiality": "NONE",
  "useMachineId": true,
  "allowNullSessionFallBack": true,
  "allowOnlineID": true,
  "supportedEncryptionTypes": ["DES_CBC_CRC"],
  "noLMHash": false,
  "lmCompatibilityLevel": "SEND_LM_NTLM_RESPONSE",
  "lDAPClientIntegrity": "NEGOTIATE_SIGNING",
  "nTLMMinClientSec": ["REQUIRE_NTLMV2_SESSION_SECURITY"],
  "nTLMMinServerSec": ["REQUIRE_NTLMV2_SESSION_SECURITY"]
}

```

---

Wartiva is in early access. Request access: https://wartiva.com/early-access.html  
All pages: https://wartiva.com/llms.txt
