Skip to content

Commit cbc401e

Browse files
committed
Acrolinx fixes
1 parent 315130a commit cbc401e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

support/windows-server/windows-security/audit-domain-controller-ntlmv1.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@ For more information, see [How to enable NTLM 2 authentication](enable-ntlm-2-au
8383

8484
## More information
8585

86-
The sign-in (logon) operation that Event ID 4624 records doesn't use NTLMv1 session security. There's actually no session security, because no key material exists.
86+
The sign-in (logon) operation that Event ID 4624 describes doesn't use NTLMv1 session security. There's actually no session security, because no key material exists.
8787

8888
The logic of the NTLM Auditing is that it logs NTLMv2-level authentication when it finds NTLMv2 key material on the sign-in session. It logs NTLMv1 in all other cases, which include anonymous sessions. Therefore, our general recommendation is to ignore the event for security protocol usage information when the event is logged for **ANONYMOUS LOGON**.
8989

0 commit comments

Comments
 (0)