Network Access: Services using Local System when reverting to NTLM authentication must use computer identity

0b49395c-beb5-480b-a1b8-1096622607a1

Network Access: Services using Local System that use Negotiate when reverting to NTLM authentication must use the computer identity instead of authenticating anonymously

Services using Local System that use Negotiate when reverting to NTLM authentication may gain unauthorized access if allowed to authenticate anonymously versus using the computer identity.

Remediation

To fix this configure the policy value for Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> "Network security: Allow Local System to use computer identity for NTLM" to "Enabled".
STIG:
Server 2019: https://www.stigviewer.com/stig/windows_server_2019/2020-06-15/finding/V-93295
Server 2016: https://www.stigviewer.com/stig/microsoft_windows_server_2016/2021-09-29/finding/V-225049