Policy
Log Enhanced Domain-wide NTLM Logs
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows11
This policy setting configures whether the domain controllers to which this setting is applied will log the new, enhanced domain-wide NTLM logs. These logs contain more information about NTLM authentication on a domain-wide level, including NTLMv1 usage. If enabled, domain controllers will log the new domain-wide NTLM logs. If disabled, domain controllers will not log the new domain-wide NTLM logs. If not configured, domain controllers will default to logging the new domain-wide NTLM logs. More information is available at aka.ms/ntlmlogandblock.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\Software\Policies\Microsoft\Netlogon\Parameters\EnableEnhancedDomainNtlmLogs | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- ComputerAllow cryptography algorithms compatible with Windows NT 4.0At least Windows Vista
- ComputerContact PDC on logon failureAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerSet Netlogon share compatibilityAt least Windows Server 2003
- ComputerSet scavenge intervalAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerSet SYSVOL share compatibilityAt least Windows Server 2003
- ComputerSpecify expected dial-up delay on logonAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerSpecify log file debug output levelAt least Windows Server 2003
- ComputerSpecify maximum log file sizeAt least Windows Server 2003
- ComputerSpecify negative DC Discovery cache settingAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerSpecify positive periodic DC Cache refresh for non-background callersAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerSpecify site nameAt least Windows Server 2003 operating systems or Windows XP Professional
- ComputerUse final DC discovery retry setting for background callersAt least Windows Server 2003 operating systems or Windows XP Professional