Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPassword

Information

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

If this security setting is enabled, the Server Message Block (SMB) redirector is allowed to send plaintext passwords to non-Microsoft SMB servers that do not support password encryption during authentication.

Sending unencrypted passwords is a security risk.

Default: Disabled.

Solution

Policy Path: Security Options
Policy Setting Name: Microsoft network client: Send unencrypted password to third-party SMB servers

See Also

https://techcommunity.microsoft.com/t5/microsoft-security-baselines/windows-11-version-22h2-security-baseline/ba-p/3632520

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-5

Plugin: Windows

Control ID: 7fb4baebe87784a4e553868e3d4ff49841966a2f11a1de6ab93c6ce4e8f8ae6b