Netwerkbeveiliging Minimum Sessie Security Voor Ntlm Ssp Based Including Veilige Rpc Servers Is Set To Require Ntlmv2 Sessie Security Require 128 Bit Versleuteling
📅 2025-10-30
•
⏱️ 2 minuten lezen
•
🔴 Must-Have
💼 Management Samenvatting
Deze security regelen waarborgt de correcte configuratie van beveiligingsinstellingen op Windows endpoints.
Aanbeveling
IMPLEMENT
Risico zonder
High
Risk Score
7/10
Implementatie
2u (tech: 1u)
Van toepassing op:
✓ Windows
Deze instelling is onderdeel van de Windows security baseline en beschermt tegen bekende aanvalsvectoren door het afdwingen van veilige configuraties.
Dit regelen configureert Netwerkbeveiliging minimum sessie security voor ntlm ssp based including veilige rpc servers is set to require ntlmv2 sessie security require 128 bit versleuteling via Microsoft Intune apparaat configuratie beleid of compliance beleidsregels om Windows endpoints te beveiligen volgens security best practices.
Vereisten
Microsoft Intune via device configuratiebeleidsregels
Implementatie
Gebruik PowerShell-script network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers-is-set-to-require-ntlmv2-session-security-require-128-bit-encryption.ps1 (functie Invoke-Implementation) – Implementeren.
Gebruik PowerShell-script network-security-minimum-sessie-security-for-ntlm-ssp-based-including-secure-rpc-servers-is-set-to-require-ntlmv2-sessie-security-require-128-bit-encryption.ps1 (functie Invoke-Monitoring) – Monitoren.
monitoring
Gebruik PowerShell-script network-security-minimum-sessie-security-for-ntlm-ssp-based-including-secure-rpc-servers-is-set-to-require-ntlmv2-sessie-security-require-128-bit-encryption.ps1 (functie Invoke-Monitoring) – Controleren.
Remediatie
Gebruik PowerShell-script network-security-minimum-sessie-security-for-ntlm-ssp-based-including-secure-rpc-servers-is-set-to-require-ntlmv2-sessie-security-require-128-bit-encryption.ps1 (functie Invoke-Remediation) – Herstellen.
Compliance en Auditing
Beleid documentatie
Compliance & Frameworks
CIS M365: Control 18.9.19.2 (L1) - CIS Security Benchmark aanbevelingen
BIO: 16.01 - BIO Baseline Informatiebeveiliging Overheid - 16.01 - Gebeurtenissen logging en audittrails
ISO 27001:2022: A.12.4.1 - ISO 27001:2022 - Gebeurtenissen logging en audittrails
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).
PowerShell
<#
================================================================================
POWERSHELL SCRIPT - Nederlandse Baseline voor Veilige Cloud
================================================================================
.SYNOPSIS
Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling
.DESCRIPTION
Implementeert, monitort en herstelt: Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling
.NOTES
Filename: network-security-minimum-session-security-for-ntlm-ssp-based-including-secure-rpc-servers-is-set-to-require-ntlmv2-session-security-require-128-bit-encryption.ps1
Author: Nederlandse Baseline voor Veilige Cloud
Version: 1.0
Workload: intune
Category: security-options
#>
#Requires -Version 5.1
[CmdletBinding()]
param()
$ErrorActionPreference = 'Stop'
function Invoke-Implementation {
<#
.SYNOPSIS
Implementeert de configuratie
#>
[CmdletBinding()]
param()
Write-Host "[INFO] Invoke-Implementation - Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling" -ForegroundColor Cyan
Invoke-Remediation
}
function Invoke-Monitoring {
<#
.SYNOPSIS
Controleert de huidige configuratie status
#>
[CmdletBinding()]
param()
try {
Write-Host "
========================================" -ForegroundColor Cyan
Write-Host "Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling - Monitoring" -ForegroundColor Cyan
Write-Host "========================================" -ForegroundColor Cyan
# TODO: Implementeer monitoring logica voor Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling
Write-Host "[INFO] Monitoring check voor Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling" -ForegroundColor Yellow
Write-Host "[OK] Monitoring check completed" -ForegroundColor Green
}
catch {
Write-Error "Monitoring failed: $_"
throw
}
}
function Invoke-Remediation {
<#
.SYNOPSIS
Herstelt de configuratie naar de gewenste staat
#>
[CmdletBinding()]
param()
try {
Write-Host "
========================================" -ForegroundColor Cyan
Write-Host "Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling - Remediation" -ForegroundColor Cyan
Write-Host "========================================" -ForegroundColor Cyan
# TODO: Implementeer remediation logica voor Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling
Write-Host "[INFO] Remediation voor Netwerkbeveiliging Minimum sessie Security voor Ntlm Ssp Based Including veilige Rpc Servers Is Set To Require Ntlmv2 sessie Security Require 128 Bit versleuteling" -ForegroundColor Yellow
Write-Host "[OK] Remediation completed" -ForegroundColor Green
}
catch {
Write-Error "Remediation failed: $_"
throw
}
}