Locked areas in group policy


there areas of group policy locked down.  one example lan manager hash value.  is there way unlock them?

i have tried change lm hash in registry setting reverts enabled on reboot.

my goal here disable "do not store lm hash value" , disable smb signing make domain compatible dos based machine tools.  i realize i'll take security hit here, small (1 server, 40 workstations) private network.  please advise.

thank you

hi richard,

before going further, worth noticing known there security risk if disable do not store lan manager hash value on next password change and smb signing.

if have enabled thedo not store lan manager hash value on next password change from active directory group policy, local policy of setting greyed out.

to check out, may run command gpresult /v >c:\gpresult.txt see in gpo policy has been enabled, , can disable setting in gpo.

regarding setting, following article may referred information.

network security: not store lan manager hash value on next password change

http://technet.microsoft.com/en-us/library/jj852276.aspx

regarding how disable smb signing, following article may referred more information.

modify security policies in default domain controllers policy

http://technet.microsoft.com/en-us/library/cc731654(ws.10).aspx

best regards,

frank shen




Windows Server  >  Group Policy



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2