Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos
ID: 9ffe56c5-fb0f-5287-a043-3c6bbab6dcb2
STIX ID: report--9ffe56c5-fb0f-5287-a043-3c6bbab6dcb2
Feed Name: The Hacker News
Microsoft outlined a three-phase strategy to phase out NTLM in favor of Kerberos to improve enterprise authentication security: (1) enhanced NTLM auditing for visibility (available now), (2) addressing migration blockers with features like IAKerb and Local KDC and prioritizing Kerberos in core components (expected H2 2026), and (3) disabling NTLM by default in the next Windows Server/client with opt-in re-enablement controls. Despite NTLM’s formal deprecation in June 2024, its continued use poses risks such as replay, relay, and pass-the-hash attacks; organizations are urged to audit usage, map dependencies, migrate to Kerberos, test NTLM-off configurations, and enable Kerberos upgrades.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
