<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-Security-NTLM" version="10.0.10586.212" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="Resources">
    <dependentAssembly>
      <assemblyIdentity name="Microsoft-Windows-Security-NTLM.Resources" version="10.0.10586.212" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
  </dependency>
  <file name="msv1_0.dll" destinationPath="$(runtime.system32)\" sourceName="msv1_0.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">mNM8cs7vssClXCMtzzHL9fifp+0rG0UAkVsQLcza6zo=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="LsaPackages" />
      <categoryInstance subcategory="Authentication Packages">
        <package xmlns="urn:schemas-microsoft-com:asm.v3" name="msv1_0" position="last" />
      </categoryInstance>
      <categoryInstance subcategory="Security Packages">
        <package xmlns="urn:schemas-microsoft-com:asm.v3" name="msv1_0" position="last" />
      </categoryInstance>
    </categoryMembership>
  </memberships>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0">
      <registryValue name="Auth132" valueType="REG_SZ" value="IISSUBA" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="description1" value="Implements the NTLM authentication component." />
        <string id="displayName0" value="NTLM" />
        <string id="event_ACCESS_CONTROL_RESTRICTION_NTLM_ACCOUNT_LOGON_FAILURE" value="NTLM authentication failed because access control restrictions are required.%n%nAccount Name:%t%1%nDevice Name:%t%2%nError Code:%t%3%n%nAuthentication Policy Information:%n%tSilo Name:%t%4%n%tPolicyName:%t%5" />
        <string id="event_PROTECTED_USER_NTLM_ACCOUNT_LOGON_FAILURE" value="NTLM authentication failed because the account was a member of the Protected User group.%n%nAccount Name:%t%1%nDevice Name:%t%2%nError Code:%t%3" />
        <string id="eventAuthenticationProviderName" value="Microsoft-Windows-Authentication" />
        <string id="eventProviderName" value="Microsoft-Windows-NTLM" />
        <string id="NTLMAuthFallbackToWeakNtowf" value="NTLM client used the domain password. The attempt to use the DC-generated NTLM secret failed, and fallback to the domain password succeeded.%nAccount Name:%t%1%nDevice Name:%t%2%n" />
        <string id="NTLMChannelName" value="Microsoft-Windows-NTLM/Operational" />
        <string id="NTLMClientBlocked" value="NTLM client blocked: Outgoing NTLM authentication traffic to remote servers that is blocked.%nTarget server: %1%nSupplied user: %2%nSupplied domain: %3%nPID of client process: %4%nName of client process: %5%nLUID of client process: %6%nUser identity of client process: %7%nDomain name of user identity of client process: %8%nMechanism OID: %9%n%nNTLM authentication requests from this computer are blocked.%n%nIf you want to allow this computer to use NTLM authentication, set the security policy Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers to Allow all.%n%nIf you want only the target server %1 to accept NTLM authentication requests from this computer, set the security policy Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers to Deny all and then set the security policy Network Security: Restrict NTLM: Add remote server exceptions and list the target server %1 as an exception to use NTLM authentication." />
        <string id="NTLMClientBlockedAudit" value="NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked.%nTarget server: %1%nSupplied user: %2%nSupplied domain: %3%nPID of client process: %4%nName of client process: %5%nLUID of client process: %6%nUser identity of client process: %7%nDomain name of user identity of client process: %8%nMechanism OID: %9%n%nAudit the NTLM authentication requests from this computer that would be blocked by the target server %1 if the security policy Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers is set to Deny all.%n%nIf you want all servers to accept NTLM authentication requests from this computer, set the security policy Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers to Allow all.%n%nIf you want only the target server %1 to accept NTLM authentication requests from this computer, set the security policy Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers to Deny all, and then set the security policy Network Security: Restrict NTLM: Add remote server exceptions and list the target server %1 as an exception to use NTLM authentication." />
        <string id="NTLMMinimumClientSecurity" value="NTLM Minimum Client Security Block:%nCalling process PID: %1%nCalling Process Name: %2%nNegotiated Security Flags: %3%nMinimum Security Flags: %4" />
        <string id="NTLMMinimumServerSecurity" value="NTLM Minimum Server Security Block:%nCalling process PID: %1%nCalling Process Name: %2%nNegotiated Security Flags: %3%nMinimum Security Flags: %4" />
        <string id="NTLMServerBlockedChallenge" value="NTLM server blocked: Incoming NTLM traffic to servers that is blocked%nCalling process PID: %1%nCalling process name: %2%nCalling process LUID: %3%nCalling process user identity: %4%nCalling process domain identity: %5%nMechanism OID: %6%n%nNTLM authentication requests to this server have been blocked.%n%nIf you want this server to allow NTLM authentication, set the security policy Network Security: Restrict NTLM: Incoming NTLM Traffic to Allow all." />
        <string id="NTLMServerBlockedChallengeAudit" value="NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked%nCalling process PID: %1%nCalling process name: %2%nCalling process LUID: %3%nCalling process user identity: %4%nCalling process domain identity: %5%nMechanism OID: %6%n%nAudit NTLM authentication requests to this server that would be blocked if the security policy Network Security: Restrict NTLM: Incoming NTLM Traffic is set to Deny all accounts or Deny all domain accounts.%n%nIf you want this server to allow NTLM authentication, set the security policy Network Security: Restrict NTLM: Incoming NTLM Traffic to Allow all." />
        <string id="NTLMServerBlockedHigher" value="NTLM server blocked in the domain: NTLM authentication in this domain that is blocked%nUser: %1%nDomain: %2%nWorkstation: %3%nPID: %4%nProcess: %5%nLogon type: %6%nInProc: %7%nMechanism: %8%n%nNTLM authentication within the domain %2 is blocked.%n%nIf you want to allow NTLM authentication requests in the domain %1, set the security policy Network Security: Restrict NTLM: NTLM authentication in this domain to Disabled.%n%nIf you want to allow NTLM authentication requests only to specific servers in the domain %1, set the security policy Network Security: Restrict NTLM: NTLM authentication in this domain to Deny for domain servers or Deny domain accounts to domain servers, and then set the security policy Network Security: Restrict NTLM: Add server exceptions in this domain to define a list of servers in this domain as an exception to use NTLM authentication." />
        <string id="NTLMServerBlockedHigherAudit" value="NTLM server blocked in the domain audit: Audit NTLM authentication in this domain%nUser: %1%nDomain: %2%nWorkstation: %3%nPID: %4%nProcess: %5%nLogon type: %6%nInProc: %7%nMechanism: %8%n%nAudit NTLM authentication requests within this domain that would be blocked if the security policy Network Security: Restrict NTLM: NTLM authentication in this domain is set to Deny for domain servers or Deny domain accounts to domain servers.%n%nIf you want to allow NTLM authentication requests in the domain %1, set the security policy Network Security: Restrict NTLM: NTLM authentication in this domain to Disabled.%n%nIf you want to allow NTLM authentication requests to specific servers in the domain %1, set the security policy Network Security: Restrict NTLM: NTLM authentication in this domain to Deny for domain servers or Deny domain accounts to domain servers, and then set the security policy Network Security: Restrict NTLM: Add server exceptions in this domain to define a list of servers in this domain to use NTLM authentication." />
        <string id="task_CATEGORY_AUDITNTLM" value="Auditing NTLM" />
        <string id="task_CATEGORY_BLOCKNTLM" value="Blocking NTLM" />
        <string id="task_CATEGORY_MAX_CATEGORY" value="Max" />
      </stringTable>
    </resources>
  </localization>
  <instrumentation>
    <events xmlns="http://schemas.microsoft.com/win/2004/08/events">
      <provider guid="{AC43300D-5FCC-4800-8E99-1BD3F85F0320}" message="$(string.eventProviderName)" messageFileName="%SystemRoot%\System32\msv1_0.dll" name="Microsoft-Windows-NTLM" resourceFileName="%SystemRoot%\System32\msv1_0.dll" symbol="NTLMEventProviderId">
        <channels>
          <channel chid="NTLM" enabled="true" isolation="System" message="$(string.NTLMChannelName)" name="Microsoft-Windows-NTLM/Operational" type="Operational" />
          <importChannel chid="ProtectedUserFailuresDC" name="Microsoft-Windows-Authentication/ProtectedUserFailures-DomainController" />
          <importChannel chid="AuthenticationPolicyFailuresDC" name="Microsoft-Windows-Authentication/AuthenticationPolicyFailures-DomainController" />
        </channels>
        <tasks>
          <task message="$(string.task_CATEGORY_BLOCKNTLM)" name="CATEGORY_BLOCKNTLM" symbol="CATEGORY_BLOCKNTLM" value="0x0001" />
          <task message="$(string.task_CATEGORY_AUDITNTLM)" name="CATEGORY_AUDITNTLM" symbol="CATEGORY_AUDITNTLM" value="0x0002" />
          <task message="$(string.task_CATEGORY_MAX_CATEGORY)" name="CATEGORY_MAX_CATEGORY" symbol="CATEGORY_MAX_CATEGORY" value="0x0003" />
        </tasks>
        <templates>
          <template tid="T_NTLMLESS_CLIENT_BLOCK">
            <data inType="win:UnicodeString" name="TargetName" />
            <data inType="win:UnicodeString" name="UserName" />
            <data inType="win:UnicodeString" name="DomainName" />
            <data inType="win:UInt32" name="CallerPID" />
            <data inType="win:UnicodeString" name="ProcessName" />
            <data inType="win:HexInt64" name="ClientLUID" />
            <data inType="win:UnicodeString" name="ClientUserName" />
            <data inType="win:UnicodeString" name="ClientDomainName" />
            <data inType="win:UnicodeString" name="MechanismOID" />
          </template>
          <template tid="T_NTLMLESS_SERVER_BLOCK_CHALLENGE">
            <data inType="win:UInt32" name="CallerPID" />
            <data inType="win:UnicodeString" name="ProcessName" />
            <data inType="win:HexInt64" name="ClientLUID" />
            <data inType="win:UnicodeString" name="ClientUserName" />
            <data inType="win:UnicodeString" name="ClientDomainName" />
            <data inType="win:UnicodeString" name="MechanismOID" />
          </template>
          <template tid="T_NTLMLESS_SERVER_BLOCK_HIGHER">
            <data inType="win:UnicodeString" name="UserName" />
            <data inType="win:UnicodeString" name="DomainName" />
            <data inType="win:UnicodeString" name="Workstation" />
            <data inType="win:UInt32" name="CallerPID" />
            <data inType="win:UnicodeString" name="ProcessName" />
            <data inType="win:UInt32" name="LogonType" />
            <data inType="win:Boolean" name="InProc" />
            <data inType="win:UnicodeString" name="MechanismOID" />
          </template>
          <template tid="T_MINIMUM_NTLM_SECURITY">
            <data inType="win:UInt32" name="CallerPID" />
            <data inType="win:UnicodeString" name="ProcessName" />
            <data inType="win:HexInt32" name="NegotiatedSecurity" />
            <data inType="win:HexInt32" name="RequiredSecurity" />
          </template>
          <template tid="T_PROTECTED_USER_NTLM_ACCOUNT_LOGON_FAILURE">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="DeviceName" />
            <data inType="win:HexInt32" name="Status" />
          </template>
          <template tid="T_ACCESS_CONTROL_RESTRICTION_NTLM_ACCOUNT_LOGON_FAILURE">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="DeviceName" />
            <data inType="win:HexInt32" name="Status" />
            <data inType="win:UnicodeString" name="SiloName" />
            <data inType="win:UnicodeString" name="PolicyName" />
          </template>
          <template tid="T_AUTH_FALLBACK_TO_WEAK_NTOWF">
            <data inType="win:UnicodeString" name="AccountName" />
            <data inType="win:UnicodeString" name="DeviceName" />
          </template>
        </templates>
        <events>
          <event channel="NTLM" level="win:Warning" message="$(string.NTLMClientBlocked)" symbol="NTLMClientBlocked" task="CATEGORY_BLOCKNTLM" template="T_NTLMLESS_CLIENT_BLOCK" value="4001" />
          <event channel="NTLM" level="win:Informational" message="$(string.NTLMClientBlockedAudit)" symbol="NTLMClientBlockedAudit" task="CATEGORY_AUDITNTLM" template="T_NTLMLESS_CLIENT_BLOCK" value="8001" />
          <event channel="NTLM" level="win:Warning" message="$(string.NTLMServerBlockedChallenge)" symbol="NTLMServerBlockedChallenge" task="CATEGORY_BLOCKNTLM" template="T_NTLMLESS_SERVER_BLOCK_CHALLENGE" value="4002" />
          <event channel="NTLM" level="win:Informational" message="$(string.NTLMServerBlockedChallengeAudit)" symbol="NTLMServerBlockedChallengeAudit" task="CATEGORY_AUDITNTLM" template="T_NTLMLESS_SERVER_BLOCK_CHALLENGE" value="8002" />
          <event channel="NTLM" level="win:Warning" message="$(string.NTLMServerBlockedHigher)" symbol="NTLMServerBlockedHigher" task="CATEGORY_BLOCKNTLM" template="T_NTLMLESS_SERVER_BLOCK_HIGHER" value="4003" />
          <event channel="NTLM" level="win:Informational" message="$(string.NTLMServerBlockedHigherAudit)" symbol="NTLMServerBlockedHigherAudit" task="CATEGORY_AUDITNTLM" template="T_NTLMLESS_SERVER_BLOCK_HIGHER" value="8003" />
          <event channel="NTLM" level="win:Warning" message="$(string.NTLMMinimumClientSecurity)" symbol="NTLMMinimumClientSecurity" template="T_MINIMUM_NTLM_SECURITY" value="4010" />
          <event channel="NTLM" level="win:Warning" message="$(string.NTLMMinimumServerSecurity)" symbol="NTLMMinimumServerSecurity" template="T_MINIMUM_NTLM_SECURITY" value="4011" />
          <event channel="NTLM" level="win:Informational" message="$(string.NTLMAuthFallbackToWeakNtowf)" symbol="NTLMAuthFallbackToWeakNtowf" template="T_AUTH_FALLBACK_TO_WEAK_NTOWF" value="4012" />
          <event channel="ProtectedUserFailuresDC" level="win:Error" message="$(string.event_PROTECTED_USER_NTLM_ACCOUNT_LOGON_FAILURE)" symbol="ProtectedUserNTLMAccountLogonFailure" template="T_PROTECTED_USER_NTLM_ACCOUNT_LOGON_FAILURE" value="100" />
          <event channel="AuthenticationPolicyFailuresDC" level="win:Error" message="$(string.event_ACCESS_CONTROL_RESTRICTION_NTLM_ACCOUNT_LOGON_FAILURE)" symbol="AccessControlRestrictionNTLMAccountLogonFailure" template="T_ACCESS_CONTROL_RESTRICTION_NTLM_ACCOUNT_LOGON_FAILURE" value="101" />
        </events>
      </provider>
    </events>
  </instrumentation>
  <migration settingsVersion="0">
    <supportedComponents>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" language="*" name="Microsoft-Windows-Security-NTLM" processorArchitecture="*" settingsVersionRange="0" />
        <migXml xmlns="">
          <rules context="System">
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0\* [*]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [UseMachineId]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisallowMsvChapv2]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LimitBlankPasswordUse]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisableLoopbackCheck]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DebugBreakIfDebugged]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [OldPasswordAllowedPeriod]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LmCompatibilityLevel]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" language="*" name="Microsoft-Windows-Security-NTLM-DL" processorArchitecture="*" settingsVersionRange="0" />
        <migXml xmlns="">
          <rules context="System">
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0\* [*]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [UseMachineId]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisallowMsvChapv2]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LimitBlankPasswordUse]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisableLoopbackCheck]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DebugBreakIfDebugged]</pattern>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [OldPasswordAllowedPeriod]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" language="*" name="Microsoft-Windows-Security-NTLM-LMC" processorArchitecture="*" settingsVersionRange="0" />
        <migXml xmlns="">
          <rules context="System">
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LmCompatibilityLevel]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
    </supportedComponents>
    <migXml xmlns="">
      <rules context="System">
        <include>
          <objectSet>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0\* [*]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LmCompatibilityLevel]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [UseMachineId]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisallowMsvChapv2]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LimitBlankPasswordUse]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisableLoopbackCheck]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DebugBreakIfDebugged]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [OldPasswordAllowedPeriod]</pattern>
          </objectSet>
        </include>
        <merge script="MigXmlHelper.SourcePriority()">
          <objectSet>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0\* [*]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [UseMachineId]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisallowMsvChapv2]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LimitBlankPasswordUse]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DisableLoopbackCheck]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [DebugBreakIfDebugged]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [OldPasswordAllowedPeriod]</pattern>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa [LmCompatibilityLevel]</pattern>
          </objectSet>
        </merge>
      </rules>
    </migXml>
  </migration>
  <configuration xmlns="urn:schemas-microsoft-com:asm.v3" xmlns:app="NTLMSchema" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
    <configurationSchema>
      <xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="NTLMSchema" targetNamespace="NTLMSchema">
        <xsd:element name="Msv1_0" type="xsd:string" wcm:handler="regtree('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LmCompatibilityLevel" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="UseMachineId" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="DisallowMsvChapv2" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="1" name="LimitBlankPasswordUse" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="DisableLoopbackCheck" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="DebugBreakIfDebugged" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="OldPasswordAllowedPeriod" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="536870912" name="NtlmMinClientSec" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element default="536870912" name="NtlmMinServerSec" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="AllowS4UForDomainUsers" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="NtLmInfoLevel" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LogToFile" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="IPAddressRefreshInterval" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="HostedTargetsRefreshInterval" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MappedDomain" type="xsd:string" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="PreferredDomain" type="xsd:string" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="BackConnectionHostNames" type="wcm:multiString" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Msv1_0')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
      </xsd:schema>
    </configurationSchema>
  </configuration>
</assembly>