You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
msv1_0
About this tag
The msv1_0 tag on WindowsForum.com covers discussions about the MSV1_0 authentication package, which handles NTLM authentication in Windows. Recent content focuses on Microsoft's plan to audit and enforce a block on NTLMv1-derived credentials in Windows 11 24H2 and Windows Server 2025. This change introduces a new registry key (BlockNtlmv1SSO) and new NTLM event IDs for audit versus enforce behavior. The rollout begins with auditing in late 2025 and moves to default enforcement for unmanaged devices by October 2026. Topics include how to detect NTLMv1 usage, who is affected, and why this security update matters for enterprise environments.
Microsoft will audit and then begin enforcing a block on NTLMv1–derived credentials in Windows 11, version 24H2 and Windows Server 2025: the change is gated by a new registry key (BlockNtlmv1SSO), exposes two new NTLM event IDs for Audit vs Enforce behavior, and will be rolled out in phases...