Policy
Block NTLM (LM, NTLM, NTLMv2)
This policy controls if the SMB client will block NTLM for remote connection authentication. If you enable this policy setting, the SMB client won't use NTLM for remote connection authentication. If you disable or do not configure this policy setting, the SMB client can still use NTLM.
PackMicrosoft Windows
CategoryNetwork / Lanman Workstation
Policy ID
5bdea4597e3eInternal name
Pol_BlockNTLMRegistry
Copy registry mappings
HKLM\Software\Policies\Microsoft\Windows\LanmanWorkstation\BlockNTLM (enabled) = 1
HKLM\Software\Policies\Microsoft\Windows\LanmanWorkstation\BlockNTLM (disabled) = 0Policy notes
This policy controls if the SMB client will block NTLM for remote connection authentication. If you enable this policy setting, the SMB client won't use NTLM for remote connection authentication. If you disable or do not configure this policy setting, the SMB client can still use NTLM.
Related policies
Alternative Port MappingsAudit insecure guest logonAudit server does not support encryptionAudit server does not support signingBlock NTLM Server Exception ListCipher suite orderDisable SMB compressionDisabled SMB over QUIC Server Exception ListEnable Alternative PortsEnable insecure guest logonsEnable remote mailslotsEnable SMB over QUICHandle Caching on Continuous Availability SharesMandate the maximum version of SMBMandate the minimum version of SMBOffline Files Availability on Continuous Availability SharesRequire EncryptionUse SMB compression by default