How can I use the local security settings to force NTLMv2?
Note: The following information is intended for
registered local support providers (LSPs) at Indiana
University. If you are an LSP and have questions regarding the
information in this document, contact LSP Services at
lsps@iu.edu ; otherwise, contact your campus
Support Center.
The instructions below are manual steps to change a setting that the IUware IUWindowsAuthUpdate tool changes automatically. If you're not familiar with the Microsoft Management Console or the Local Security Policy interface, download and use the tool from IUware Online rather than following the steps below.
Note: Windows 7 and Vista default to using NTLMv2 authentication.
To use the local security settings to force Windows XP and 2000 to use NTLMv2:
- Open the Local Security Policy console, using one of the following
methods:
-
From the Control Panel, through Administrative
Tools:
- From the
Startmenu, selectControl Panel(Windows XP default view) orSettingsand thenControl Panel(Windows 2000 or 2003, or Windows XP Classic View). - Double-click
Administrative Tools, and thenLocal Security Policy.
- From the
-
Through the
Rundialog box:
- From the
Startmenu, selectRun.... - In the
Open...field, enter: secpol.msc - Click
OK.
- From the
The Local Security Policy console will appear.
-
From the Control Panel, through Administrative
Tools:
- Find "Network Security: LAN Manager authentication level", which
is located in
Security Settings, Local Policies, Security Options.
- Set the LAN Manager authentication level to
NTLMv2 response only/refuse LM and NTLM.
Last modified on October 27, 2009.







