Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

OpenClaw bug allows one-click remote code execution via malicious link

Microsoft begins phasing out NTLM with three-phase plan to migrate Windows to Kerberos

Ring offers “Search Party” feature to help non-Ring camera owners find lost dogs

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Microsoft begins phasing out NTLM with three-phase plan to migrate Windows to Kerberos
Identity

Microsoft begins phasing out NTLM with three-phase plan to migrate Windows to Kerberos

userBy userFebruary 2, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananFebruary 2, 2026Kerberos / Enterprise Security

Microsoft has announced a three-phase approach to phasing out New Technology LAN Manager (NTLM) as part of its efforts to migrate Windows environments to more powerful Kerberos-based options.

The development comes more than two years after the tech giant revealed plans to retire its legacy technology due to vulnerabilities that could facilitate relay attacks and allow malicious parties to gain unauthorized access to network resources. NTLM will be officially deprecated in June 2024 and will no longer receive updates.

“NTLM consists of security protocols originally designed to provide authentication, integrity, and confidentiality to users,” explains Mariam Gewida, second technical program manager at Microsoft. “However, as security threats have evolved, so have standards to meet modern security expectations. NTLM now uses weak encryption, making it susceptible to a variety of attacks, including replay and man-in-the-middle attacks.”

Microsoft said that despite its deprecated status, the use of NTLM remains prevalent in enterprise environments where modern protocols like Kerberos cannot be implemented due to legacy dependencies, network limitations, or built-in application logic. This exposes organizations to security risks such as replay, relay, and pass-the-hash attacks.

cyber security

To mitigate this issue in a secure manner, the company has adopted a three-step strategy that paves the way for disabling NTLM by default.

Phase 1: Build visibility and control with enhanced NTLM auditing to better understand where and why NTLM is still being used (available now) Phase 2: Address common roadblocks to NTLM migration through features such as IAKerb and Local Key Distribution Centers (KDCs) (pre-release), as well as update core Windows components to prioritize Kerberos authentication (planned for 2H 2026) Phase 3: Disabling NTLM in the next version Windows Server and associated Windows clients have issues and require explicit re-enablement with new policy controls

Microsoft sees this transition as a major step toward a passwordless, phishing-resistant future. Additionally, organizations that rely on NTLM should conduct audits, map dependencies, migrate to Kerberos, test NTLM-off configurations in non-production environments, and enable Kerberos upgrades.

“Disabling NTLM by default does not yet mean completely removing NTLM from Windows,” Gewida said. “Instead, it means that Windows is delivered secure by default, with network NTLM authentication blocked and automatically disabled.”

“The OS will prioritize modern, more secure Kerberos-based alternatives, while common legacy scenarios will be addressed through new upcoming features such as local KDC and IAKerb (pre-release).”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRing offers “Search Party” feature to help non-Ring camera owners find lost dogs
Next Article OpenClaw bug allows one-click remote code execution via malicious link
user
  • Website

Related Posts

OpenClaw bug allows one-click remote code execution via malicious link

February 2, 2026

Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats

February 2, 2026

Protecting the middle market throughout the threat lifecycle

February 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

OpenClaw bug allows one-click remote code execution via malicious link

Microsoft begins phasing out NTLM with three-phase plan to migrate Windows to Kerberos

Ring offers “Search Party” feature to help non-Ring camera owners find lost dogs

Carbon Robotics built an AI model to detect and identify plants

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.