Block NetBIOS-based discovery for domain controller location
Jump to overview

Policy overview

Key metadata and intent for this policy.

Computer
Category
System > Net Logon > DC Locator DNS Records
Supported on
Windows10

This policy setting allows you to control whether domain controller (DC) location algorithm uses NetBIOS_based discovery for domain controller location. If you enable or do not configure this policy setting, the DC location algorithm will never use NetBIOS-based discovery. This is the default behavior. If you disable this policy setting, the DC location algorithm may use NetBIOS-based discovery when necessary. The final behavior is further governed by the AvoidFallbackNetbiosDiscovery setting. NetBIOS-based discovery is considered unsecure, has many limitations, and will be deprecated in a future release. For these reasons, NetBIOS-based discovery is not recommended. See https://aka.ms/dclocatornetbiosdeprecation for more information.

Internal name
Netlogon_BlockNetbiosDiscovery
Policy ID
b83afc295b10
Elements
0

Registry values

How enabled and disabled states update the registry.

ScopeRegistry locationTypeEnabled valueDisabled valueCopy
Computer
Path
Software\Policies\Microsoft\Netlogon\Parameters
Value name
BlockNetbiosDiscovery
REG_DWORD
HKLM
1
HKLM
0
Registry location
Type REG_DWORD · Computer
Path
Software\Policies\Microsoft\Netlogon\Parameters
Value name
BlockNetbiosDiscovery
Hive
HKLM
Enabled value
1
Disabled value
0

Policy elements

Inputs and configuration options exposed by this policy.

This policy has no additional user input fields.