en-US windows-security computer

Network security: LAN Manager authentication level

Verified with Windows Security Options 25H2 — updated on July 13, 2026

Security policy

This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.

Path in the GPO console

Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Network security

Description

This setting selects which LM or NTLM responses the computer sends and which protocols it accepts. Current Windows clients normally use NTLMv2 responses, while domain or baseline policy may enforce a stricter level. Higher levels reduce exposure to obsolete hashes and downgrade attacks, but can break authentication with legacy systems.

Registry

HKLM System\CurrentControlSet\Control\Lsa

Value name: LmCompatibilityLevel

More options available

Options

Network security: LAN Manager authentication level
LmCompatibilityLevel enum
  • Send LM & NTLM responses -> 0
  • Send LM & NTLM - use NTLMv2 session security if negotiated -> 1
  • Send NTLM response only -> 2
  • Send NTLMv2 response only -> 3
  • Send NTLMv2 response only. Refuse LM -> 4
  • Send NTLMv2 response only. Refuse LM & NTLM -> 5

Export Builder

BETA

Configure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.

These exports write the registry — this is not a managed GPO.

Security policy setting: a domain GPO (Security Settings) can overwrite this registry value at the next policy refresh. Prefer configuring it via GPMC > Security Options.

.reg file

Windows Registry Editor Version 5.00

; Exported from gporais.com
; Policy: Network security: LAN Manager authentication level
; State: Enabled

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa]
"LmCompatibilityLevel"=dword:00000001
"LmCompatibilityLevel"=dword:00000000
More formats (PowerShell, Intune, SCCM)

PowerShell

# Exported from gporais.com
# Policy: Network security: LAN Manager authentication level
# State: Enabled

$path = 'HKLM:\System\CurrentControlSet\Control\Lsa'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'LmCompatibilityLevel' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'LmCompatibilityLevel' -Value 0 -Type DWord

Embed this policy on your site

What to embed
Theme

Adds one script line: the theme follows your site’s appearance and the height fits the content. If your site blocks scripts, the embed follows the visitor’s system theme.

Preview