Policy

Block NetBIOS-based discovery for domain controller location

This policy setting allows you to control whether domain controller (DC) location algorithm uses NetBIOS_based discovery for domain controller location. If you enable or do not configure this policy setting, the DC location algorithm will never use NetBIOS-based discovery. This is the default behavior. If you disable this policy setting, the DC location algorithm may use NetBIOS-based discovery when necessary. The final behavior is further governed by the AvoidFallbackNetbiosDiscovery setting. NetBIOS-based discovery is considered unsecure, has many limitations, and will be deprecated in a future release. For these reasons, NetBIOS-based discovery is not recommended. See https://aka.ms/dclocatornetbiosdeprecation for more information.

Policy
Pack Microsoft Windows
Category System / Net Logon / DC Locator DNS Records
Policy ID b83afc295b10
Internal name Netlogon_BlockNetbiosDiscovery

Registry

Copy registry mappings

HKLM\Software\Policies\Microsoft\Netlogon\Parameters\BlockNetbiosDiscovery (enabled) = 1
HKLM\Software\Policies\Microsoft\Netlogon\Parameters\BlockNetbiosDiscovery (disabled) = 0

Policy notes

This policy setting allows you to control whether domain controller (DC) location algorithm uses NetBIOS_based discovery for domain controller location. If you enable or do not configure this policy setting, the DC location algorithm will never use NetBIOS-based discovery. This is the default behavior. If you disable this policy setting, the DC location algorithm may use NetBIOS-based discovery when necessary. The final behavior is further governed by the AvoidFallbackNetbiosDiscovery setting. NetBIOS-based discovery is considered unsecure, has many limitations, and will be deprecated in a future release. For these reasons, NetBIOS-based discovery is not recommended. See https://aka.ms/dclocatornetbiosdeprecation for more information.

Related policies