Stop NTLM relay: LDAP, SMB signing and LLMNR
Harden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.
NTLM relay remains one of the most reliable paths to domain compromise because so many AD environments still permit unsigned LDAP binds, unsigned SMB, and legacy name resolution protocols that leak credentials to anyone listening on the local segment. None of the fixes here require new infrastructure — they are registry values, Group Policy settings, and audit logging you can enable this week. This guide covers locking down LDAP and SMB signing, killing LLMNR/NBT-NS, and retiring NTLMv1, with verification steps and a clear list of what breaks.
Why LLMNR and NBT-NS enable NTLM relay
LLMNR (Link-Local Multicast Name Resolution) and NBT-NS (NetBIOS Name Service) let Windows hosts resolve names when DNS fails, by broadcasting a request to the local subnet. Any host on that segment can answer — there is no authentication on the response. An attacker who answers these broadcasts induces the victim to authenticate to them with NTLM, capturing a hash or relaying the live authentication attempt to a target service such as LDAP or SMB. Turning off both protocols removes the easiest credential-harvesting foothold in most internal penetration tests.
Disable LLMNR
Group Policy path:
Computer Configuration > Policies > Administrative Templates > Network > DNS Client
Turn Off Multicast Name Resolution: EnabledEquivalent registry value:
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient
EnableMulticast (DWORD) = 0Disable NBT-NS
NBT-NS has no native GPO toggle; disable it per adapter via WMI, ideally pushed with a startup script or scheduled task so it survives new NICs:
# Disable NetBIOS over TCP/IP on all adapters (0 = default/enable via DHCP, 1 = enable, 2 = disable)
Get-WmiObject Win32_NetworkAdapterConfiguration -Filter "IPEnabled=True" |
ForEach-Object { $_.SetTcpipNetbios(2) }Verification:
Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" -Name EnableMulticast
Get-WmiObject Win32_NetworkAdapterConfiguration -Filter "IPEnabled=True" |
Select-Object Description, TcpipNetbiosOptionsLDAP signing and LDAP channel binding
Unsigned LDAP binds allow an attacker to relay a captured NTLM authentication straight into an LDAP session on a domain controller, often enough to add themselves to a privileged group or read confidential attributes. Two independent settings close this: LDAP server signing (LDAPServerIntegrity) and LDAP channel binding (LdapEnforceChannelBinding), the latter closing the LDAPS/TLS-specific relay path that signing alone does not cover.
Set on every domain controller:
HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
LDAPServerIntegrity (DWORD) = 2 ; 1 = None, 2 = Require signing
HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
LdapEnforceChannelBinding (DWORD) = 2 ; 0 = Never, 1 = When supported, 2 = AlwaysBoth can be pushed via a GPO registry preference targeting the Domain Controllers OU, or set directly:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" -Name LDAPServerIntegrity -Value 2
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" -Name LdapEnforceChannelBinding -Value 2Find non-compliant clients before enforcing
Before setting LDAPServerIntegrity to require signing, enable diagnostic logging on the DC and review the Directory Service event log for a rollout window (two to four weeks is typical):
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics" -Name "16 LDAP Interface Events" -Value 2Watch for these Directory Service event IDs, which identify exactly which clients and services are binding without signing or channel binding:
| Event ID | Meaning |
|---|---|
| 2886 | DC is not currently configured to require LDAP signing — informational, remediate before enforcing |
| 2887 | Count of unsigned SASL and cleartext simple binds accepted in the last 24 hours |
| 2888 | Signing is enforced — count of unsigned binds rejected in the last 24 hours |
| 2889 | A specific client performed an unsigned SASL bind or cleartext simple bind — logs the client IP and account, your remediation punch list |
| 3039 | A specific client bound over TLS without a valid channel binding token (3040 is the 24-hour count, 3041 means channel binding is not enforced) |
Get-WinEvent -LogName "Directory Service" | Where-Object { $_.Id -in 2887,2889,3039 } |
Select-Object TimeCreated, Id, Message | Format-ListOnly move LDAPServerIntegrity and LdapEnforceChannelBinding to their enforcing values (2) once events 2889 and 3039 stop firing, or the remaining sources are accepted exceptions. See LDAP channel binding for the mechanics of how binding ties the LDAP session to the TLS channel.
SMB signing
SMB relay works the same way as LDAP relay: a captured NTLM authentication is replayed against a file server or, worse, a domain controller's SMB stack. Requiring SMB signing means a relayed session fails integrity checks and is dropped.
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
Microsoft network server: Digitally sign communications (always): Enabled
Microsoft network client: Digitally sign communications (always): EnabledRegistry equivalents:
HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters
RequireSecuritySignature (DWORD) = 1
HKLM\SYSTEM\CurrentControlSet\Services\LanManWorkstation\Parameters
RequireSecuritySignature (DWORD) = 1Apply to domain controllers first (they are the highest-value relay target), then workstations and file servers in a phased rollout. Verify:
Get-SmbServerConfiguration | Select-Object RequireSecuritySignature
Get-SmbClientConfiguration | Select-Object RequireSecuritySignatureAuditing and restricting NTLM
Rather than disabling NTLM outright — which breaks anything that hasn't migrated to Kerberos — use the Restrict NTLM audit-then-enforce workflow.
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
Network security: Restrict NTLM: Audit NTLM authentication in this domain: Enable all
Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers: Audit allAudit events (IDs 8001-8004) land in the Microsoft-Windows-NTLM/Operational log, not the System log. Review for a full business cycle, build an allow list of services that legitimately still need NTLM, then move from Audit to Deny for everything else:
Network security: Restrict NTLM: NTLM authentication in this domain: Deny all
Network security: Restrict NTLM: Add server exceptions in this domain: <legacy app servers>Disable NTLMv1
NTLMv1 is cryptographically weak and should be disabled outright; only NTLMv2 needs to remain available as a fallback for equipment that can't yet reach Kerberos.
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
Network security: LAN Manager authentication level: Send NTLMv2 response only. Refuse LM & NTLMRegistry:
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
LmCompatibilityLevel (DWORD) = 5Verify:
Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa" -Name LmCompatibilityLevelWhat it breaks
- LDAP signing/channel binding: older network scanners, printers/MFDs with embedded LDAP address-book lookups, some backup and monitoring appliances, and third-party identity bridges that bind without signing. Events 2886-2889 identify these before you enforce.
- SMB signing: very old SMBv1-only NAS devices and some industrial/embedded systems; signing overhead also has a minor throughput cost on high-volume file transfer over slow links.
- LLMNR/NBT-NS disablement: environments still relying on NetBIOS name resolution for legacy flat-name lookups (pre-DNS applications, some line-of-business software) may see intermittent name resolution failures — check DNS coverage first.
- LmCompatibilityLevel = 5: any device or application hardcoded to NTLMv1, typically very old copiers, some SCADA/ICS gear, and unpatched non-Windows SMB clients.
For related hardening, see Kerberos hardening and Domain controller hardening. Background on the relay technique itself is covered at NTLM relay.
Frequently asked questions
Will enforcing LDAP signing break anything?
It breaks any application or appliance that binds to LDAP in clear text without signing support, including some older network scanners, printers, and third-party identity connectors. Test in audit mode using events 2886-2889 before enforcing.
What is the difference between LDAP signing and LDAP channel binding?
LDAP signing (LDAPServerIntegrity) protects LDAP traffic on port 389 from tampering and relay. Channel binding (LdapEnforceChannelBinding) ties an LDAPS (port 636) session to the underlying TLS channel, closing a separate relay path that signing alone does not cover.
Can I disable NTLM entirely?
In most environments, no — legacy applications, workgroup devices, and some VPN or print services still depend on NTLM. The realistic path is audit, then Restrict NTLM policies scoped to what you've verified is safe, alongside disabling NTLMv1 everywhere.
Stop NTLM relay: LDAP, SMB signing and LLMNR