Skip to content
arrow_back
search
ISM-1055 policy ASD Information Security Manual (ISM)

Disable Insecure LAN Manager Authentication

Systems must disable outdated LAN Manager and NT LAN Manager authentication to enhance security.

record_voice_over

Plain language

This control is about turning off old, insecure ways of logging into computers and systems, known as LAN Manager and NT LAN Manager. These methods are outdated and can be easily hacked, putting your sensitive information at risk if they remain active.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

LAN Manager and NT LAN Manager authentication methods are disabled.
policy ASD Information Security Manual (ISM) ISM-1055
priority_high

Why it matters

If LAN Manager/NTLM authentication remains enabled, attackers can force downgrades and capture weak hashes, enabling credential cracking and unauthorised access.

settings

Operational notes

Verify Group Policy/security options disable LM and NTLMv1, and monitor for policy drift so legacy authentication methods are not re-enabled by updates.

Mapping detail

Mapping

Direction

Controls