Forum Discussion
Root DFS and ntlm hardening
The selected setting is not NTLM hardening: “Send LM and NTLM, use NTLMv2 session security if negotiated” still allows LM and NTLM authentication. The intermittent failure of the domain DFS root, while child paths work, points toward inconsistent domain-controller referral or authentication paths rather than an unhealthy namespace. Enable NTLM auditing before denying anything and review the NTLM Operational log on domain controllers and namespace servers. During a failure, record the active domain controller, inspect the DFS referral cache, verify DNS and domain-controller connectivity, and test TCP 445 to the referred namespace server. Compare those results with a working attempt and check whether existing mapped paths contain stale referrals. Entra-joined devices that are not AD computer objects can follow a different authentication path, so confirm how the user obtains Kerberos tickets. Correct the inconsistent dependency first, then apply a consistent NTLMv2-only or deny policy in stages.