Information
This policy setting determines whether NTLM is allowed to fall back to a NULL session when used with LocalSystem.
The recommended state for this setting is: Disabled.
Rationale:
NULL sessions are less secure because by definition they are unauthenticated.
Impact:
None - this is the default behavior. Any applications that require NULL sessions for LocalSystem will not work as designed.
Solution
To establish the recommended configuration via GP, set the following UI path to Disabled:
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Network security: Allow LocalSystem NULL session fallback
Default Value:
Disabled. (NTLM will not be permitted to fall back to a NULL session when used with LocalSystem.)