Microsoft network client: Send unencrypted password to third-party SMB servers - EnablePlainTextPassword

Information

Microsoft network client: Send unencrypted password to connect to third-party SMB servers

If this security setting is enabled, the Server Message Block (SMB) redirector is allowed to send plaintext passwords to non-Microsoft SMB servers that do not support password encryption during authentication.

Sending unencrypted passwords is a security risk.

Default: Disabled.

Solution

Policy Path: Local Policies\Security Options
Policy Name: Microsoft network client: Send unencrypted password to third-party SMB servers

See Also

https://www.microsoft.com/en-us/download/details.aspx?id=55319

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-5(7), CSCv6|13

Plugin: Windows

Control ID: d1160b79c0cf5a481150fd5bd0a4a8568c40278179ca9131c1f8240d8860bb1b