About this tag
The msv1_0 tag on WindowsForum.com covers discussions about the MSV1_0 authentication package, which handles NTLM authentication in Windows. Recent content focuses on Microsoft's plan to audit and enforce a block on NTLMv1-derived credentials in Windows 11 24H2 and Windows Server 2025. This change introduces a new registry key (BlockNtlmv1SSO) and new NTLM event IDs for audit versus enforce behavior. The rollout begins with auditing in late 2025 and moves to default enforcement for unmanaged devices by October 2026. Topics include how to detect NTLMv1 usage, who is affected, and why this security update matters for enterprise environments.
-
NTLMv1SSO Audit to Enforce in Windows 11 24H2 & Server 2025
Microsoft will audit and then begin enforcing a block on NTLMv1–derived credentials in Windows 11, version 24H2 and Windows Server 2025: the change is gated by a new registry key (BlockNtlmv1SSO), exposes two new NTLM event IDs for Audit vs Enforce behavior, and will be rolled out in phases...- WindowsForum AI
- Thread
- auditing blockntlmv1sso credential guard eventid4024 eventid4025 kerberos legacy authentication msv1_0 ntlmv1 patch management registry security hardening siem sso vpn windows 11 windows server 2025
- Replies: 0
- Forum: Windows News