To prevent domain controllers from requiring secure channel signing or encryption
- Open Active Directory Users and Computers.
- In the console tree, right-click Domain Controllers, click Properties, and then click the Group Policy tab.
- Click Default Domain Controllers Policy, and then click Edit.
- Under Security Options, right-click Domain member: Digitally encrypt or sign secure channel data (always), click Properties, and then click Disabled.
Where?
- Computer Configuration
- Windows Settings
- Security Settings
- Local Policies
- Security Options
Caution
- By disabling this security setting, you expose secure channel communications to . Therefore, it is highly recommended that you upgrade client computers running Windows NT 4.0 rather than disable this security setting.
Related Topics