Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos
    Cybersecurity

    Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos

    adminBy adminFebruary 2, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananFeb 02, 2026Kerberos / Enterprise Security

    Microsoft has announced a three-phase approach to phase out New Technology LAN Manager (NTLM) as part of its efforts to shift Windows environments toward stronger, Kerberos-based options.

    The development comes more than two years after the tech giant revealed its plans to deprecate the legacy technology, citing its susceptibility to weaknesses that could facilitate relay attacks and allow bad actors to gain unauthorized access to network resources. NTLM was formally deprecated in June 2024 and no longer receives updates.

    “NTLM consists of security protocols originally designed to provide authentication, integrity, and confidentiality to users,” Mariam Gewida, Technical Program Manager II at Microsoft, explained. “However, as security threats have evolved, so have our standards to meet modern security expectations. Today, NTLM is susceptible to various attacks, including replay and man-in-the-middle attacks, due to its use of weak cryptography.”

    Despite the deprecated status, Microsoft said it continues to find the use of NTLM prevalent in enterprise environments where modern protocols like Kerberos cannot be implemented due to legacy dependencies, network limitations, or ingrained application logic. This, in turn, exposes organizations to security risks, such as replay, relay, and pass-the-hash attacks.

    Cybersecurity

    To mitigate this problem in a secure manner, the company has adopted a three-phase strategy that paves the way for NTLM to be disabled by default –

    • Phase 1: Building visibility and control using enhanced NTLM auditing to better understand where and why NTLM is still being used (Available now)
    • Phase 2: Addressing common roadblocks that prevent a migration to NTLM through features like IAKerb and local Key Distribution Center (KDC) (pre-release), as well as updating core Windows components to prioritize Kerberos authentication (Expected in H2 2026)
    • Phase 3: Disabling NTLM in the next version of Windows Server and associated Windows client, and requiring explicit re-enablement through new policy controls

    Microsoft has positioned the transition as a major step toward a passwordless, phishing-resistant future. This also requires organizations relying on NTLM to conduct audits, map dependencies, migrate to Kerberos, test NTLM-off configurations in non-production environments, and enable Kerberos upgrades.

    “Disabling NTLM by default does not mean completely removing NTLM from Windows yet,” Gewida said. “Instead, it means that Windows will be delivered in a secure-by-default state where network NTLM authentication is blocked and no longer used automatically.”

    “The OS will prefer modern, more secure Kerberos-based alternatives. At the same time, common legacy scenarios will be addressed through new upcoming capabilities such as Local KDC and IAKerb (pre-release).”

    Begins Kerberos Microsoft Move NTLM PhaseOut Plan ThreeStage Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWhy experience now shapes search visibility
    Next Article AI, security tailwinds signal promising 2026 for Cisco
    admin
    • Website

    Related Posts

    How Threat Actors Vet Stolen Credit Card Shops

    April 18, 2026

    Another DraftKings Hacker Sentenced to Prison

    April 18, 2026

    Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    This open-source smart home system is slowly overtaking Alexa and Google Home

    April 18, 2026

    I asked ChatGPT to find me a free movie and didn’t expect this

    April 18, 2026

    10 Tools That Give Me Back 4 Hours Every Day (2026)

    April 18, 2026

    How Threat Actors Vet Stolen Credit Card Shops

    April 18, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,377)
    • Privacy & Online Earning (171)
    • SEO & Digital Marketing (844)
    • Tech Tools & Mobile / Apps (1,645)
    • WiFi / Internet & Networking (230)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    This open-source smart home system is slowly overtaking Alexa and Google Home

    April 18, 2026

    I asked ChatGPT to find me a free movie and didn’t expect this

    April 18, 2026

    10 Tools That Give Me Back 4 Hours Every Day (2026)

    April 18, 2026
    Most Popular
    • This open-source smart home system is slowly overtaking Alexa and Google Home
    • I asked ChatGPT to find me a free movie and didn’t expect this
    • 10 Tools That Give Me Back 4 Hours Every Day (2026)
    • How Threat Actors Vet Stolen Credit Card Shops
    • Google Ads tests direct Google Tag Manager integration for conversion setup
    • TikTok 44.8.15 beta APK Download by TikTok Pte. Ltd.
    • Another DraftKings Hacker Sentenced to Prison
    • This ‘surprising’ Lenovo Chromebook has crashed back to a Black Friday price at Best Buy
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.