Microsoft to disable NTLM by default in future Windows releases
ID: 377e215f-c5f9-543f-a9b6-7c94dfb57132
STIX ID: report--377e215f-c5f9-543f-a9b6-7c94dfb57132
Feed Name: Bleeping Computer
Threat Score
Microsoft announced it will disable network NTLM authentication by default in upcoming Windows Server and client releases due to persistent security weaknesses and widespread exploitation (NTLM relay attacks, pass-the-hash). The company outlined a three-phase transition—enhanced auditing, new features like IAKerb and Local KDC, then disabling network NTLM by default—while noting NTLM will remain present and can be re-enabled by policy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
