The following NTLM setting is being set to "Deny All" on our Windows servers.
Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options\Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers
It's generating numerous NTLM logs on the servers, it seems to be during each poll from the SW apps:
NTLM server blocked in the domain audit: Audit NTLM authentication in this domain
User: SolarWinds AD Service Account name ..
Does this cause an issue with the SolarWinds app or node monitors or does it recognize that NTLM is being blocked and uses an alternate communication method? WMI is the primary polling method of the nodes.