Skip to main content

2026 年 8 月 24 日

NTLM Authentication for App Volumes

Omnissa App Volumes uses NTLM 2 (NTLM version 2) to identify and authenticate computer and user windows sessions. The NTLM mechanism allows Windows to provide App Volumes Manager information about the computer and user. App Volumes Manager uses this information for identification purpose.

App Volumes Manager uses LDAPS and channel binding. For information about LDAP channel binding, see the Microsoft documentation.

Channel binding tokens make LDAP authentication over SSL or TLS more secure against man-in-the-middle attacks.

Configure LmCompatibilityLevel (LAN Manager authentication level) in your Domain Controller

By default, LmCompatibilityLevel, a policy setting, is set to 5 in Windows Server 2016 and later. However, this setting is not compatible with the App Volumes NTLM 2 implementation. As a result, the domain controller rejects all NTLM authentication requests.

To ensure that NTLM authentication requests are accepted, LmCompatibilityLevel must be set to 3 when configuring each domain controller host in App Volumes.

Note: Changing this setting might affect compatibility with other services and applications in your environment. Ensure that you first test the change in a non-production environment and later apply the changed setting in a production environment.

For more information about the setting including the location, best practices, considerations, and so on, see the (Microsoft documentation - Network security: LAN Manager authentication level)[https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-security-lan-manager-authentication-level].

To add and configure domain controller hosts, see Adding and Configuring Domain Controller Hosts.

此页面对您有帮助吗?

对本主题提供反馈

本主题对您有帮助吗?

请勿填写任何个人信息或机密信息。

正在生成链接…