Summary
Within SCCM’s client push installation properties, there exists a setting to “Allow connection fallback to NTLM” (Figure 1).
Figure 1 - Client Push Installation Properties
Linked Defensive IDs
Associated Offensive IDs
- ELEVATE-2: NTLM relay via automatic client push installation
- ELEVATE-3: NTLM relay via automatic client push installation and AD System Discovery