Forum Discussion
Root DFS and ntlm hardening
Hi
Long story short of where we are.
After a lot of investigationg and comparing settings we discovered that our intuned client machines have Sent NTLM v2 and refuse lm and ntlm settings enabled as well as require 128 bit encryption and ntlmv2. Servers were inconsistent so we set them all to send lm and ntlm and send ntlmv2 if negotiated with the other settings set to no minimum. This did not resolve the problem. We then tested each DC and we dicovered that only one answered and others failed. The only difference between that DC and other was Network Security: Restrict NTLM: Incoming NTLM traffic. The working DC had a setting of Deny all domain accounts while other servers had Deny All accounts. Once we changed that we were able to aloways load the \\domain.co.uk path.
Now obviously this is not the most secure way of doing this but how would i now go on about resolving this issue and making secure and my cyber team happy?
In addition to the below can you let me know how i would do this:
"confirm how the user obtains Kerberos tickets"
Thank you in advance.
Regards