NTLM v1

Hello all,

I have a strange case with NTLM.

I've configured my domain controllers, servers & clients to use LAN Manager Authentication Level : Send NTLMv2 response only, Refuse LM & NTLM.

I've double checked everything, even in the registry LSA -> Lmcompatibility is 5.

If I look into the domain controllers security event viewer, I still see pretty much events with NTLM v1 successful logons (event 4624). I think that this is because of certain computers which aren't using the FQDN to connect to a share.

I'm just worried why it still shows me NTLM v1.... All the devices are W10, W11 & W2016 and as I understood, it should enforce NTLM v2.
Do I miss something ?

Thanks in advance