2.3.11.7 Ensure 'Network security: LAN Manager authentication level' is set to 'Send NTLMv2 response only. Refuse LM & NTLM'

Information

LAN Manager (LM) is a family of early Microsoft client/server software that allows users to link personal computers together on a single network. The default setting on servers allows all clients to authenticate with servers and use their resources. However, this means that LM responses -- the weakest form of authentication response -- are sent over the network, and it is potentially possible for attackers to sniff that traffic to more easily reproduce the user's password.

Solution

Make sure 'Network security: LAN Manager authentication level' is set to send NTLMv2 response only and refuse LM and NTLM.

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(6), CSCv6|13

Plugin: Windows

Control ID: 770a6256dbcf8905e1d9308ad45b21ed335f601eb8509e1df3a65d9b29bb5b8d