microsoft / CSS-Exchange

Exchange Server support tools and scripts
MIT License
1.21k stars 332 forks source link

Health Checker to collect SuppressExtendedProtection registry key and report #2032

Closed dpaulson45 closed 2 months ago

dpaulson45 commented 4 months ago

Is your request related to a problem? Please describe. In a customer's environment, it was reported that this key was set to a value of 3 and it would cause EMS to fail to launch along with other issues they were facing.

https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/authentication-fails-non-windows-ntlm-kerberos-server

Need to add this to Health Checker and report if it is set. Need to do some lab testing to verify if other protocols even work, as that would determine if this should be flagged as a security risk or not, as things could just be broken to connect, thus making it 'secure' because it doesn't work.

Additional context NA