How to Disable TLS 1.0 and TLS 1.1 via Group Policy
- Open regedit utility
Open Group Policy Management (gpmc.msc) in a Domain Controller.
data:image/s3,"s3://crabby-images/bfc88/bfc88cca944683986a5e72fff11e8e35a13229c4" alt="Open regedit utility"
2. Creating a GPO in the Domain Controller
Navigate to the OU where Policy is to be linked and right-click and select ‘Create a GP in this domain and Link it here’; In this demo select ‘Domain Controllers’ OU.
data:image/s3,"s3://crabby-images/d4c94/d4c94aa1fcfeff6da4445e2c4663febb16104d29" alt="Creating a GPO in the Domain Controller"
3. Rename the GPO to ‘Disable_TLS 1.0_TLS 1.1’
Name the New GPO and click on ‘OK’; this creates a New GP which is linked to the OU.
data:image/s3,"s3://crabby-images/29424/294243a1208bfb9e3e22ec1fefac2fa7b0e35636" alt="Rename the GPO to ‘Disable_TLS 1.0_TLS 1.1’"
4. Edit the ‘Disable_TLS 1.0_TLS 1.1’ GPO
Right-click the Policy and click on ‘Edit’.
data:image/s3,"s3://crabby-images/472a4/472a4473a5acea1639d17b7388f73044f7e02900" alt="Edit the ‘Disable_TLS 1.0_TLS 1.1’ GPO"
5. Create Registry Item in Group Policy
Navigate to Computer Configurations –> Preferences –> Windows Settings –> Registry.
Create a new Registry by Right click on the blank space and selecting New –> Registry Item.
data:image/s3,"s3://crabby-images/e6a29/e6a29a8ce94c6be387211d03c747d65e20b77350" alt="Create Registry Item in Group Policy"
6. Update Registry Properties
In new Registry Properties, update the details as below and click on ‘OK’.
Action: Update
Hive: HKEY_LOCAL_MACHINE
Key Path: SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client
Value name: Enabled
Value type: REG_DWORD
Value data: 0
Base: Hexadecimal
data:image/s3,"s3://crabby-images/497f8/497f8fa3b29db31e88886b2b52b6312d67bee7af" alt="Update Registry Properties"
7. [OPTIONAL] Commands to create Registry Item in Group Policy
Similar to above step, create below keys to Disable TLS 1.0 as well as TLS 1.1,
![[OPTIONAL] Commands to create Registry Item in Group Policy](https://miro.medium.com/v2/resize:fit:700/0*MM9Q3YfHpgsZCHBm.png)
8. [OPTIONAL] List of Registry Items in Group Policy
The image shows the list of Registry items created in Group Policy.
![[OPTIONAL] List of Registry Items in Group Policy](https://miro.medium.com/v2/resize:fit:700/0*xlxphJpgEiXvs7jH.png)
We hope this post would help you know how to disable TLS 1.0 and TLS 1.1 via Group Policy to enhance the security of your infrastructure.
Ref: How to Disable TLS 1.0 and TLS 1.1 via Group Policy – The Sec Master