Skip to content
04 · NTLM & Legacy ProtocolsPart 1 of 5Foundation

Stop NTLM relay: LDAP, SMB signing and LLMNR

Harden LDAP signing, LDAP channel binding, SMB signing, and disable LLMNR/NBT-NS to shut down NTLM relay paths against domain controllers.

Florian Amette5 min read

NTLM relay remains one of the most reliable paths to domain compromise because so many AD environments still permit unsigned LDAP binds, unsigned SMB, and legacy name resolution protocols that leak credentials to anyone listening on the local segment. None of the fixes here require new infrastructure — they are registry values, Group Policy settings, and audit logging you can enable this week. This guide covers locking down LDAP and SMB signing, killing LLMNR/NBT-NS, and retiring NTLMv1, with verification steps and a clear list of what breaks.

Why LLMNR and NBT-NS enable NTLM relay

LLMNR (Link-Local Multicast Name Resolution) and NBT-NS (NetBIOS Name Service) let Windows hosts resolve names when DNS fails, by broadcasting a request to the local subnet. Any host on that segment can answer — there is no authentication on the response. An attacker who answers these broadcasts induces the victim to authenticate to them with NTLM, capturing a hash or relaying the live authentication attempt to a target service such as LDAP or SMB. Turning off both protocols removes the easiest credential-harvesting foothold in most internal penetration tests.

Disable LLMNR

Group Policy path:

Text
Computer Configuration > Policies > Administrative Templates > Network > DNS Client
  Turn Off Multicast Name Resolution: Enabled

Equivalent registry value:

Text
HKLM\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient
  EnableMulticast (DWORD) = 0

Disable NBT-NS

NBT-NS has no native GPO toggle; disable it per adapter via WMI, ideally pushed with a startup script or scheduled task so it survives new NICs:

PowerShell
# Disable NetBIOS over TCP/IP on all adapters (0 = default/enable via DHCP, 1 = enable, 2 = disable)
Get-WmiObject Win32_NetworkAdapterConfiguration -Filter "IPEnabled=True" |
    ForEach-Object { $_.SetTcpipNetbios(2) }

Verification:

PowerShell
Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient" -Name EnableMulticast
Get-WmiObject Win32_NetworkAdapterConfiguration -Filter "IPEnabled=True" |
    Select-Object Description, TcpipNetbiosOptions

LDAP signing and LDAP channel binding

Unsigned LDAP binds allow an attacker to relay a captured NTLM authentication straight into an LDAP session on a domain controller, often enough to add themselves to a privileged group or read confidential attributes. Two independent settings close this: LDAP server signing (LDAPServerIntegrity) and LDAP channel binding (LdapEnforceChannelBinding), the latter closing the LDAPS/TLS-specific relay path that signing alone does not cover.

Set on every domain controller:

Text
HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
  LDAPServerIntegrity (DWORD) = 2   ; 1 = None, 2 = Require signing

HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters
  LdapEnforceChannelBinding (DWORD) = 2   ; 0 = Never, 1 = When supported, 2 = Always

Both can be pushed via a GPO registry preference targeting the Domain Controllers OU, or set directly:

PowerShell
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" -Name LDAPServerIntegrity -Value 2
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" -Name LdapEnforceChannelBinding -Value 2

Find non-compliant clients before enforcing

Before setting LDAPServerIntegrity to require signing, enable diagnostic logging on the DC and review the Directory Service event log for a rollout window (two to four weeks is typical):

PowerShell
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics" -Name "16 LDAP Interface Events" -Value 2

Watch for these Directory Service event IDs, which identify exactly which clients and services are binding without signing or channel binding:

Event IDMeaning
2886DC is not currently configured to require LDAP signing — informational, remediate before enforcing
2887Count of unsigned SASL and cleartext simple binds accepted in the last 24 hours
2888Signing is enforced — count of unsigned binds rejected in the last 24 hours
2889A specific client performed an unsigned SASL bind or cleartext simple bind — logs the client IP and account, your remediation punch list
3039A specific client bound over TLS without a valid channel binding token (3040 is the 24-hour count, 3041 means channel binding is not enforced)
PowerShell
Get-WinEvent -LogName "Directory Service" | Where-Object { $_.Id -in 2887,2889,3039 } |
    Select-Object TimeCreated, Id, Message | Format-List

Only move LDAPServerIntegrity and LdapEnforceChannelBinding to their enforcing values (2) once events 2889 and 3039 stop firing, or the remaining sources are accepted exceptions. See LDAP channel binding for the mechanics of how binding ties the LDAP session to the TLS channel.

SMB signing

SMB relay works the same way as LDAP relay: a captured NTLM authentication is replayed against a file server or, worse, a domain controller's SMB stack. Requiring SMB signing means a relayed session fails integrity checks and is dropped.

Text
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
  Microsoft network server: Digitally sign communications (always): Enabled
  Microsoft network client: Digitally sign communications (always): Enabled

Registry equivalents:

Text
HKLM\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters
  RequireSecuritySignature (DWORD) = 1

HKLM\SYSTEM\CurrentControlSet\Services\LanManWorkstation\Parameters
  RequireSecuritySignature (DWORD) = 1

Apply to domain controllers first (they are the highest-value relay target), then workstations and file servers in a phased rollout. Verify:

PowerShell
Get-SmbServerConfiguration | Select-Object RequireSecuritySignature
Get-SmbClientConfiguration | Select-Object RequireSecuritySignature

Auditing and restricting NTLM

Rather than disabling NTLM outright — which breaks anything that hasn't migrated to Kerberos — use the Restrict NTLM audit-then-enforce workflow.

Text
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
  Network security: Restrict NTLM: Audit NTLM authentication in this domain: Enable all
  Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers: Audit all

Audit events (IDs 8001-8004) land in the Microsoft-Windows-NTLM/Operational log, not the System log. Review for a full business cycle, build an allow list of services that legitimately still need NTLM, then move from Audit to Deny for everything else:

Text
Network security: Restrict NTLM: NTLM authentication in this domain: Deny all
Network security: Restrict NTLM: Add server exceptions in this domain: <legacy app servers>

Disable NTLMv1

NTLMv1 is cryptographically weak and should be disabled outright; only NTLMv2 needs to remain available as a fallback for equipment that can't yet reach Kerberos.

Text
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
  Network security: LAN Manager authentication level: Send NTLMv2 response only. Refuse LM & NTLM

Registry:

Text
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
  LmCompatibilityLevel (DWORD) = 5

Verify:

PowerShell
Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa" -Name LmCompatibilityLevel

What it breaks

  • LDAP signing/channel binding: older network scanners, printers/MFDs with embedded LDAP address-book lookups, some backup and monitoring appliances, and third-party identity bridges that bind without signing. Events 2886-2889 identify these before you enforce.
  • SMB signing: very old SMBv1-only NAS devices and some industrial/embedded systems; signing overhead also has a minor throughput cost on high-volume file transfer over slow links.
  • LLMNR/NBT-NS disablement: environments still relying on NetBIOS name resolution for legacy flat-name lookups (pre-DNS applications, some line-of-business software) may see intermittent name resolution failures — check DNS coverage first.
  • LmCompatibilityLevel = 5: any device or application hardcoded to NTLMv1, typically very old copiers, some SCADA/ICS gear, and unpatched non-Windows SMB clients.

For related hardening, see Kerberos hardening and Domain controller hardening. Background on the relay technique itself is covered at NTLM relay.

Frequently asked questions

Will enforcing LDAP signing break anything?

It breaks any application or appliance that binds to LDAP in clear text without signing support, including some older network scanners, printers, and third-party identity connectors. Test in audit mode using events 2886-2889 before enforcing.

What is the difference between LDAP signing and LDAP channel binding?

LDAP signing (LDAPServerIntegrity) protects LDAP traffic on port 389 from tampering and relay. Channel binding (LdapEnforceChannelBinding) ties an LDAPS (port 636) session to the underlying TLS channel, closing a separate relay path that signing alone does not cover.

Can I disable NTLM entirely?

In most environments, no — legacy applications, workgroup devices, and some VPN or print services still depend on NTLM. The realistic path is audit, then Restrict NTLM policies scoped to what you've verified is safe, alongside disabling NTLMv1 everywhere.

Stop NTLM relay: LDAP, SMB signing and LLMNR

Related guides

NTLM & Legacy Protocols

Audit and restrict NTLM in Active Directory

A step-by-step NTLM reduction plan: audit with events 8001-8004, fix the causes, build an exception list, remove NTLMv1 and set LmCompatibilityLevel 5.

Advanced
NTLM & Legacy Protocols

Require SMB signing and disable SMBv1 domain-wide

Enforce SMB signing on clients and servers, understand Windows 11 24H2 and Server 2025 defaults, audit SMBv1 use, and remove it without breaking file access.

Foundation
NTLM & Legacy Protocols

Enforce LDAP signing and channel binding on DCs

Roll out LDAP signing and channel binding with evidence: collect events 2887, 2889 and 3039, fix clients, then set LdapEnforceChannelBinding safely.

Intermediate