Locked areas in group policy
there areas of group policy locked down. one example lan manager hash value. is there way unlock them?
i have tried change lm hash in registry setting reverts enabled on reboot.
my goal here disable "do not store lm hash value" , disable smb signing make domain compatible dos based machine tools. i realize i'll take security hit here, small (1 server, 40 workstations) private network. please advise.
thank you
hi richard,
before going further, worth noticing known there security risk if disable do not store lan manager hash value on next password change and smb signing.
if have enabled thedo not store lan manager hash value on next password change from active directory group policy, local policy of setting greyed out.
to check out, may run command gpresult /v >c:\gpresult.txt see in gpo policy has been enabled, , can disable setting in gpo.
regarding setting, following article may referred information.
network security: not store lan manager hash value on next password change
http://technet.microsoft.com/en-us/library/jj852276.aspx
regarding how disable smb signing, following article may referred more information.
modify security policies in default domain controllers policy
http://technet.microsoft.com/en-us/library/cc731654(ws.10).aspx
best regards,
frank shen
Windows Server > Group Policy
Comments
Post a Comment