> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/ams/v3.0/help-and-support/support-articles/kb000007.md).

# KB000007: Adding JIT groups via Group Policy doesn't work with NTLM Disabled

## Summary

When NTLM is restricted (specifically, *outgoing* NTLM) on a workstation or server, JIT groups added via Group Policy may not apply correctly.

## Cause

NTLM is often disabled on Windows using the following Group Policy settings found in `Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options`:

* Network security: Restrict NTLM: Incoming NTLM traffic – "Deny All Accounts"
* Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers – "Deny All"

Another Group Policy setting, [commonly appearing in configuration benchmarks](https://www.unifiedcompliance.com/products/search-controls/control/8526/), is known to cause issues when NTLM is restricted: "Enable RPC Endpoint Mapper Client Authentication"

At the time of writing (August 2023), Microsoft documentation [states that](https://learn.microsoft.com/en-us/windows-server/security/rpc-interface-restrict#enableauthepresolution) these two settings are **incompatible**.

## Resolution

To quote Microsoft's [documentation](https://learn.microsoft.com/en-us/windows-server/security/rpc-interface-restrict#enableauthepresolution):

> It's encouraged to move away from NTLM to better secure your environment. If faced with a choice between restricting NTLM and using `EnableAuthEpResolution`, the recommended approach is that you restrict NTLM in your environment.

Once RPC Endpoint Mapper Client Authentication (`EnableAuthEpResolution`) is disabled, groups should sucessfully apply using Group Policy after a reboot.

## Detailed Explanation

When making changes to Local Users and Groups via GPO, Windows needs to be aware of the *security identifier* (SID) of the group.

Typically, when a group is added to a local group on a computer via GPO, the SID is *precomputed*, as the exact group to be added is already known. However, when the name of the group contains a variable - such as `%computername%` - SIDs are not pre-computed in the policy (as the group name will depend on the machine itself).

As a result, Windows uses the [LsaLookupNames2](https://learn.microsoft.com/en-us/windows/win32/api/ntsecapi/nf-ntsecapi-lsalookupnames2) function from `ntsecapi.h` to transform security group *names* (e.g. `DOMAIN\Group`) into *security identifiers* (SIDs) on the client.

The first part of this process is for the client to connect to a domain controller and call Endpoint Mapper (TCP 135). This allows the client to identify the port on which to connect to the [MS-LSAT](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-lsat/1ba21e6f-d8a9-462c-9153-4375f2020894) service.

However, when `EnableAuthEpResolution` is enabled, the RPC Endpoint Mapper Client will use NTLMSSP to authenticate to the Endpoint Mapper Service on the domain controller. As NTLM is disabled on the client, this connection fails!

This authentication failure means that the resolution of the group name fails. As a result, the group is never added to the local group on the workstation or server.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/ams/v3.0/help-and-support/support-articles/kb000007.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
