Click here to get back home

Disable ALL Lan Manager Authentication

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Disable ALL Lan Manager Authentication jeff 09-20-2005
Posted by jeff on September 20, 2005, 7:15 am
Please log in for more thread options
Hello...

I'm in a pure Windows 2003 domain environment with Windows XP clients. All
servers and workstations are joined to the domain. We are at Windows 2003
forest
functional level.

I know kerberos is the default authentication protocol. But...

I have been asked...(if possible) to completely disable all levels of Lan
Manager authentication capabilities from out environment...LM..NTLM..NTLMv2

is this possible.....?

Thanks


Posted by Steven L Umbach on September 20, 2005, 4:58 pm
Please log in for more thread options
It is not possible to completely disable it. There are also cases where it
is required such as for VPN and I also believe possibly some implementations
of Exchange. You can manage lan manager authentication level to allow only
ntlmv2 which also is a pretty robust authentication protocol though again be
careful with Exchange and VPN servers. You could also configure sensitive
domain servers [not domain controllers] with an ipsec require policy which
by default would use kerberos for computer authentication before access
would be allowed and in such case it would be impossible say for a Windows
98 or non domain computer to access the ipsec required server. Ipsec is a
fairly complex topic and must be configured correctly and tested [ideally on
a test domain], particularly for domain controllers, or all sorts of
problems will ensue. The link below is a great article on ipsec even if you
just read the appendixes which will give you an excellent understanding of
ipsec and how to use it. --- Steve

http://www.microsoft.com/technet/security/topics/architectureanddesign/ipsec/default.mspx


> Hello...
>
> I'm in a pure Windows 2003 domain environment with Windows XP clients. All
> servers and workstations are joined to the domain. We are at Windows 2003
> forest
> functional level.
>
> I know kerberos is the default authentication protocol. But...
>
> I have been asked...(if possible) to completely disable all levels of Lan
> Manager authentication capabilities from out
> environment...LM..NTLM..NTLMv2
>
> is this possible.....?
>
> Thanks




Posted by jeff on September 20, 2005, 3:43 pm
Please log in for more thread options
Thanks Steve...that is pretty much what I thought.

"Steven L Umbach" wrote:

> It is not possible to completely disable it. There are also cases where it
> is required such as for VPN and I also believe possibly some implementations
> of Exchange. You can manage lan manager authentication level to allow only
> ntlmv2 which also is a pretty robust authentication protocol though again be
> careful with Exchange and VPN servers. You could also configure sensitive
> domain servers [not domain controllers] with an ipsec require policy which
> by default would use kerberos for computer authentication before access
> would be allowed and in such case it would be impossible say for a Windows
> 98 or non domain computer to access the ipsec required server. Ipsec is a
> fairly complex topic and must be configured correctly and tested [ideally on
> a test domain], particularly for domain controllers, or all sorts of
> problems will ensue. The link below is a great article on ipsec even if you
> just read the appendixes which will give you an excellent understanding of
> ipsec and how to use it. --- Steve
>
>
http://www.microsoft.com/technet/security/topics/architectureanddesign/ipsec/default.mspx
>
>
> > Hello...
> >
> > I'm in a pure Windows 2003 domain environment with Windows XP clients. All
> > servers and workstations are joined to the domain. We are at Windows 2003
> > forest
> > functional level.
> >
> > I know kerberos is the default authentication protocol. But...
> >
> > I have been asked...(if possible) to completely disable all levels of Lan
> > Manager authentication capabilities from out
> > environment...LM..NTLM..NTLMv2
> >
> > is this possible.....?
> >
> > Thanks
>
>
>


Similar ThreadsPosted
Windows Key Manager April 3, 2006, 2:53 pm
Service control manager May 16, 2007, 6:08 pm
Users tab in Task Manager on Windows 2003 November 10, 2005, 12:28 pm
Granting Rights to Processes in Task Manager May 3, 2006, 8:15 am
Re: Remote Access Connection Manager auto-starts (and can't be stopped) July 6, 2006, 4:17 pm
disable ip address June 14, 2005, 3:17 pm
Port Disable January 2, 2007, 11:20 pm
Permanently disable SMB signing February 22, 2006, 8:09 pm
How to disable Media Pooling? June 8, 2006, 3:53 pm
Disable or rename administrator account September 1, 2006, 3:32 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap