Skip to main content

Summary

Within SCCM’s client push installation properties, there exists a setting to “Allow connection fallback to NTLM.” This setting allows the site server to fallback to NTLM if Kerberos fails (Figure 1).
Client Push Installation Properties
Adversaries commonly abuse NTLM authentication by coercing computers to authenticate to an attacker-controlled machine then either capturing or relaying the authentication to another resource. Disabling this setting prevents the use of NTLM authentication and coercion. NOTE: This technique must be used in conjunction with PREVENT-1.

Linked Defensive IDs

Associated Offensive IDs

References