Information
This policy setting determines whether the SMB redirector will send plaintext passwords during authentication to third-party SMB servers that do not support password encryption.
It is recommended that you disable this policy setting unless there is a strong business case to enable it.
If this policy setting is enabled, unencrypted passwords will be allowed across the network.
The recommended state for this setting is: 'Disabled'.
Solution
To establish the recommended configuration via GP, set the following UI path to 'Disabled':
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options\Microsoft network client: Send unencrypted password to third-party SMB servers