4.3 Ensure Windows Authentication uses Kerberos and not the NT Lan Manager (NTLM) authentication protocol

Information

If Windows Authentication mechanisms are used on SharePoint, the system should be
configured to use the Kerberos authentication protocol rather than the NT Lan Manager
(NTLM) equivalent.

Rationale:

There are a few factors in which Kerberos is superior to NTLM authentication and is indeed
preferred. First, Kerberos offers faster authentication because it does not require multiple
servers and components to complete authentication tasks, as in the case of NTLM
authentication. Second, Kerberos offers mutual authentication. Kerberos can authenticate
the client to the server and importantly, also the server to the client.

Solution

1. Launch Central Administration.
2. Click on Application Management then Manage web applications.
3. In Authentication Providers click each available zone.
4. Under Authentication Providers - Zone popup check Integrated Windows
authentication
and select Negotiate (Kerberos).

See Also

https://workbench.cisecurity.org/files/2395

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CSCv6|16.9

Plugin: Windows

Control ID: f3f2db72be9ebc599ff11b879b6c4df0deab79a1d804926b5043878aa92d8518