Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
Verified with Windows Security Options 25H2 — updated on July 13, 2026
Security policy
This is a Security Options policy (Windows Settings > Security Settings), applied by the security engine — not an Administrative Template (ADMX). In GPMC/gpedit it is configured under Local Policies > Security Options.
Path in the GPO console
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Network security Description
This bitmask specifies the minimum NTLM session protections required by client applications using NTLM SSP, including secure RPC. With no flags selected, no additional NTLMv2-session or 128-bit requirement is imposed by this setting. Requiring both protections strengthens sessions but causes negotiation to fail with peers that lack either capability.
Registry
System\CurrentControlSet\Control\Lsa\MSV1_0 Value name: NTLMMinClientSec
Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
Security policy setting: a domain GPO (Security Settings) can overwrite this registry value at the next policy refresh. Prefer configuring it via GPMC > Security Options.
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
; State: Enabled
[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\MSV1_0]
"NTLMMinClientSec"=dword:00000001
"NTLMMinClientSec"=dword:00000000 More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
# State: Enabled
$path = 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NTLMMinClientSec' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'NTLMMinClientSec' -Value 0 -Type DWord Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
# State: Enabled
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0' -Name 'NTLMMinClientSec' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0' -Name 'NTLMMinClientSec' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
# State: Enabled
$path = 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NTLMMinClientSec' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'NTLMMinClientSec' -Value 0 -Type DWord SCCM scripts
# Exported from gporais.com
# Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
# State: Enabled
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
# State: Enabled
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0' -Name 'NTLMMinClientSec' -Expected 1 -Kind DWord)
(Test-RegistryValue -Path 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0' -Name 'NTLMMinClientSec' -Expected 0 -Kind DWord)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Network security: Minimum session security for NTLM SSP based (including secure RPC) clients
# State: Enabled
$path = 'HKLM:\System\CurrentControlSet\Control\Lsa\MSV1_0'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'NTLMMinClientSec' -Value 1 -Type DWord
Set-ItemProperty -Path $path -Name 'NTLMMinClientSec' -Value 0 -Type DWord