# Microsoft NTLM Phase-Out: Detection & Migration Guidance

> As Microsoft enforces NTLM deprecation across Windows environments (beginning Windows Server 2025 and Windows 11 24H2), organizations face a critical transition-period security gap where NTLM relay, downgrade, and pass-the-hash attacks intensify against remaining NTLM dependencies. This threat focuses on DETECTION and MONITORING guidance: how defenders identify residual NTLM usage, discover legacy application dependencies, detect active NTLM relay/downgrade attacks, and build security monitoring rules that protect the environment DURING the multi-year migration from NTLM to Kerberos/certificate-based authentication. The transition period (2025-2028) is the most dangerous phase — attackers know NTLM is being phased out and are accelerating exploitation before the window closes. Distinct from TL-0018 (migration planning/enterprise enforcement), this threat covers the defensive monitoring and attack detection dimension.

- **Published:** 2026-02-02T18:12:00Z
- **Last reviewed:** 2026-02-02T18:12:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0009
- **ID:** TL-2026-0009
- **Severity:** MEDIUM (CVSS 6.5)
- **Category:** ADVISORY
- **Status:** ACTIVE
- **Detections:** 17 · **IOCs:** 36 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NTLM Detection & Monitoring During Deprecation: The Transition-Period Threat Surface

Why the Transition Period is the Most Dangerous Phase:

Microsoft's NTLM deprecation creates a paradox: the announcement signals to attackers that NTLM's days are numbered, accelerating exploitation of remaining NTLM dependencies before migration is complete. Organizations that have not yet migrated face concentrated attack pressure from adversaries racing to exploit NTLM before the window closes. Meanwhile, the migration itself introduces detection blind spots as authentication flows change.

NTLM Attack Surface — What Defenders Must Detect:

1. NTLM Relay Attacks (T1557.001):
- Attacker intercepts NTLM authentication handshake and relays it to another service
- Tools: Responder, ntlmrelayx, MultiRelay, PetitPotam, Inveigh
- Targets: SMB, LDAP, LDAPS, HTTP, MSSQL, ADCS (ESC8 — web enrollment relay)
- Detection: NTLM authentication where source IP ≠ expected client IP
- Critical: NTLM relay to ADCS (Active Directory Certificate Services) enables domain escalation
- PetitPotam forces domain controllers to authenticate to attacker-controlled SMB share

2. NTLM Downgrade Attacks:
- Attacker forces NTLMv2 authentication to downgrade to NTLMv1 (weaker, crackable)
- NTLMv1 uses DES encryption — crackable in hours on modern GPUs
- Group Policy: LmCompatibilityLevel controls NTLMv1 vs NTLMv2 enforcement
- Detection: Event ID 4624 with NtlmV1 in AuthenticationPackageName field
- Any NTLMv1 in a modern environment = either misconfiguration or active downgrade attack

3. Pass-the-Hash (T1550.002):
- Attacker uses captured NTLM hash directly for authentication without cracking
- Tools: Mimikatz, CrackMapExec, Evil-WinRM, Impacket
- NTLM hash extracted via LSASS dump, SAM database, DCSync, or network capture
- Detection: NTLM LogonType 3 (network) from workstation to server with no preceding interactive logon
- Kerberos migration eliminates PtH entirely — NTLM hash is useless against Kerberos-only systems

4. LLMNR/NBT-NS Poisoning (T1557.001):
- Attacker responds to LLMNR (UDP 5355) and NBT-NS (UDP 137) broadcast queries
- Victim sends NTLM credentials to attacker-controlled system
- Tools: Responder, Inveigh — capture NTLMv2 hashes for offline cracking or relay
- Detection: LLMNR/NBT-NS responses from non-DNS servers
- Mitigation: Disable LLMNR and NBT-NS via GPO (first step in NTLM hardening)

5. Coerced Authentication (PetitPotam, PrinterBug, DFSCoerce):
- Attacker forces a Windows service to authenticate to attacker-controlled share
- PetitPotam: MS-EFSRPC → forces machine account NTLM auth
- PrinterBug: MS-RPRN → forces print spooler NTLM auth
- DFSCoerce: MS-DFSNM → forces DFS NTLM auth
- ShadowCoerce: MS-FSRVP → forces file server NTLM auth
- Detection: Outbound NTLM authentication from domain controllers/servers to workstation IPs

6. NTLM Hash Harvesting via Malicious Documents/Links:
- UNC path in document (\\attacker\share) forces NTLM authentication
- .URL, .LNK, .SCF files with UNC paths trigger automatic NTLM auth
- Outlook preview pane rendering remote images triggers NTLM auth
- Detection: Outbound SMB connections (port 445) to external/unusual IPs

Legacy NTLM Dependency Discovery:

Before disabling NTLM, organizations must discover what still requires it:

1. NTLM Authentication Auditing:
- Enable: Audit Policy → Logon/Logoff → Audit Logon Events (Success + Failure)
- Event ID 4624 with AuthenticationPackageName 'NTLM' = active NTLM usage
- Windows Server 2025: NTLM audit mode logs all NTLM without blocking
- Group Policy: Network security: Restrict NTLM → Audit all in this domain

2. Common Legacy NTLM Dependencies:
- Older web applications using Windows Integrated Authentication (NTLM instead of Negotiate)
- Legacy printers and multifunction devices using NTLM for scan-to-folder
- Older NAS/SAN devices authenticating via NTLM
- Non-domain-joined devices that can only use NTLM (not Kerberos)
- Cross-forest trusts using NTLM when Kerberos trust is not configured
- Legacy SQL Server instances using NTLM authentication
- Third-party VPN clients using NTLM for Windows SSO
- Custom line-of-business applications hardcoded for NTLM

3. NTLM Traffic Baseline:
- Establish baseline NTLM authentication volume per service/application
- Track NTLM reduction over time as migration progresses
- Identify the 'NTLM long tail' — devices/apps that will be last to migrate
- Goal: NTLM volume trending to zero, with exceptions documented and compensated

Transition-Period Detection Strategy:

Phase 1 (Audit): Enable NTLM auditing, discover all NTLM usage, baseline volume
Phase 2 (Restrict): Block NTLM for new services, enforce Kerberos where possible
Phase 3 (Detect): Deploy detection rules for NTLM relay/downgrade/PtH on remaining NTLM
Phase 4 (Enforce): Block NTLM entirely, monitor for authentication failures
Phase 5 (Verify): Confirm zero NTLM usage, disable NTLM at domain level

Windows Security Event IDs for NTLM Monitoring:
- 4624: Successful logon (check AuthenticationPackageName for NTLM)
- 4625: Failed logon (NTLM failures during migration = legacy dependency)
- 4648: Explicit credential logon (NTLM explicit credential use)
- 8001: NTLM authentication request in domain (Server 2025 audit)
- 8002: NTLM authentication blocked (Server 2025 enforcement)
- 8003: NTLM audit-only mode log (Server 2025 transition)
- 4776: Domain controller credential validation (NTLM)
- 4769: Kerberos service ticket requested (should increase as NTLM decreases)

## MITRE ATT&CK

- T1003.003 NTDS
- T1649 Steal or Forge Authentication Certificates
- T1550.002 Pass the Hash
- T1557.001 Name Resolution Poisoning and SMB Relay
- T1187 Forced Authentication
- T1557 Adversary-in-the-Middle
- T1003 OS Credential Dumping
- T1110 Brute Force
- T1040 Network Sniffing
- T1550 Use Alternate Authentication Material
- T1021 Remote Services
- T1566 Phishing
- T1078 Valid Accounts
- T1556 Modify Authentication Process
- T1068 Exploitation for Privilege Escalation
- T1046 Network Service Discovery
- T1087 Account Discovery
- T1059 Command and Scripting Interpreter
- T1588 Obtain Capabilities
- T1552 Unsecured Credentials
- T1528 Steal Application Access Token
- T1070 Indicator Removal
- T1134 Access Token Manipulation
- T1018 Remote System Discovery
- T1069 Permission Groups Discovery
- T1047 Windows Management Instrumentation
- T1098 Account Manipulation
- T1039 Data from Network Shared Drive
- T1531 Account Access Removal

## Sources

- [Microsoft — NTLM Deprecation and Kerberos Migration Guide](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview)
- [Microsoft — Restricting NTLM Usage in Windows Environments](https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain)
- [MITRE ATT&CK — LLMNR/NBT-NS Poisoning and SMB Relay (T1557.001)](https://attack.mitre.org/techniques/T1557/001/)
- [MITRE ATT&CK — Pass the Hash (T1550.002)](https://attack.mitre.org/techniques/T1550/002/)
- [SpiderLabs — Responder: LLMNR/NBT-NS/MDNS Poisoner](https://github.com/SpiderLabs/Responder)
- [Trimarc Security — PetitPotam: NTLM Relay to ADCS (ESC8)](https://blog.truesec.com/2021/08/05/from-petitpotam-to-full-domain-compromise/)
- [SpecterOps — NTLM Relay Attacks and Defenses](https://posts.specterops.io/ntlm-relay-attacks/)
- [Microsoft — Windows Server 2025: NTLM Audit and Enforcement Modes](https://learn.microsoft.com/en-us/windows-server/whats-new/whats-new-windows-server-2025)
- [CrowdStrike — NTLM Relay Attack Detection and Prevention](https://www.crowdstrike.com/cybersecurity-101/ntlm-relay-attacks/)
- [SANS — Detecting NTLM Relay Attacks in Enterprise Environments](https://www.sans.org/white-papers/detecting-ntlm-relay/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0009
