Optional analytics cookies help us improve Hardenly. They stay off unless you accept. Cookie policy
Maturity tier — First: Basic, essential — do this before anything else.
Implementation effort: Medium - requires GPO deployment, log collection, and a review period before enforcement.
User impact: Low - auditing phase is transparent to users; impact only occurs later during enforcement.
NTLM is a legacy authentication protocol vulnerable to relay attacks, pass-the-hash, and offline cracking. Many environments still depend on it for legacy applications, printers, or scripts, so disabling it blindly can break production systems. NTLM auditing lets you discover where and how NTLM is still used before restricting or eliminating it.
Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options, setting "Network security: Restrict NTLM: Audit NTLM authentication in this domain" and "Audit Incoming NTLM Traffic" to enabled.Keep building momentum
Protect LSASS from memory dumping and credential theft attacks like Mimikatz by enforcing LSA Protection (RunAsPPL) and Credential Guard.
Sign in to vote on this item or share your rollout notes.
No comments yet — be the first to share your rollout experience.