Threat reportAdvisoryTL-2026-0018

Microsoft NTLM Deprecation - Enterprise Migration Planning Required

mediumMONITORING

Microsoft NTLM Deprecation (TL-2026-0018), also tracked as NTLM Relay, is a medium-severity advisory threat scored CVSS 6.5, first published 2026-02-02. It has no confirmed attribution, affects Microsoft Windows, maps to 26 MITRE ATT&CK techniques (T1003, T1003.003, T1018), and is covered by 16 detection rules and 47 indicators of compromise.

CVSS
6.5/10Medium
CVEs
0None referenced
Techniques
26MITRE ATT&CK
Actors
0Not attributed
Detection rules
16SPL · KQL · Sigma
IOCs
47Indicators of compromise

Key facts for TL-2026-0018

Threat ID
TL-2026-0018
Also known as
NTLM Relay, Pass-the-Hash, NTLM Deprecation
Severity
MEDIUM
CVSS
6.5 (N/A - Deprecation Advisory)
Status
MONITORING
Category
ADVISORY
First published
Last reviewed
Attribution confidence
NONE
Motivation
N/A
Target sectors
Government, Healthcare, Manufacturing, Financial Services, Education, Critical Infrastructure, Defense, Information Technology, Energy, Transportation
Target regions
Global
Detection rules
16
Indicators of compromise
47

How Microsoft NTLM Deprecation works

Microsoft officially deprecated all versions of NTLM (LANMAN, NTLMv1, NTLMv2) in June 2024, with NTLMv1 removed in Windows 11 24H2 and Windows Server 2025. This threat analyzes the enterprise migration enforcement dimension — the operational reality of eliminating a 30-year-old authentication protocol deeply embedded in Active Directory environments, legacy applications, and critical infrastructure. NTLM's deprecation eliminates the attack surface exploited by PetitPotam, PrinterBug/SpoolSample, DropTheFlam3, NTLM relay attacks, pass-the-hash, and credential theft techniques that have been the backbone of Active Directory compromise for two decades. However, migration to Kerberos/Negotiate breaks applications with hard NTLM dependencies: legacy IIS configurations, SQL Server with NTLM-only service accounts, RDP to non-domain-joined systems, network printers with NTLM-only firmware, healthcare HL7 systems, manufacturing SCADA/HMI interfaces, and government legacy applications. Microsoft's migration path (NTLM → Negotiate → Kerberos → certificate-based auth) requires enterprise-wide dependency mapping via NTLM audit logging (Event IDs 4624/4776 with LogonType analysis), GPO enforcement (LmCompatibilityLevel, RestrictSendingNTLMTraffic, AuditNTLMInDomain), and phased rollout. The enforcement timeline creates a forcing function: organizations that don't migrate will find their authentication breaking as Windows updates remove NTLM support. This is not a vulnerability patch — it is a fundamental architecture migration affecting every Windows domain on Earth.

NTLM (NT LAN Manager) is a family of authentication protocols introduced in 1993 with Windows NT 3.1. For 30+ years, NTLM has been the fallback authentication mechanism in Windows environments when Kerberos cannot be used — workgroup authentication, local logon, cross-domain trust scenarios, and any application that doesn't support Kerberos. Despite being superseded by Kerberos in Windows 2000, NTLM persisted because of deep backward compatibility requirements.

The security problem: NTLM is fundamentally flawed. It uses a challenge-response mechanism without mutual authentication (the server doesn't prove its identity to the client), enabling relay attacks. NTLMv1 uses weak DES-based cryptography, crackable in seconds. NTLMv2 improved hashing but retained the relay vulnerability. Pass-the-hash attacks exploit NTLM's hash-based authentication — an attacker with the NTLM hash never needs the actual password. These flaws have made NTLM the #1 target for Active Directory compromise:

- PetitPotam (CVE-2021-36942): Coerces Windows machines to authenticate to attacker-controlled servers via NTLM, enabling relay to Active Directory Certificate Services (AD CS) for domain takeover. - PrinterBug/SpoolSample: Abuses the Print Spooler service to coerce NTLM authentication from any Windows machine to an attacker-controlled host. - DropTheFlam3: Coerces NTLM authentication via DCOM/RPC interfaces for relay attacks. - NTLM Relay: Forwards NTLM authentication to other services (LDAP, SMB, HTTP, MSSQL) to impersonate the victim — the canonical Active Directory attack technique. - Pass-the-Hash: Uses stolen NTLM password hashes directly for authentication without knowing the plaintext password. - Responder/Inveigh: Poisons LLMNR/NBT-NS/mDNS to capture NTLM authentication attempts on the local network.

Microsoft's enforcement timeline: - June 2024: All NTLM versions deprecated (LANMAN, NTLMv1, NTLMv2). Announced alongside Windows 11 24H2. - November 2024: NTLMv1 REMOVED in Windows 11 24H2 and Windows Server 2025. MSCHAPv2 (which uses NTLMv1 primitives) only disabled via Credential Guard. - Future releases: Full NTLM removal planned. Negotiate fallback preserved during transition but will eventually be removed.

Enterprise migration complexity: The migration from NTLM to Kerberos/Negotiate is not a simple protocol swap. It requires:

1. NTLM Audit Phase — Enable audit logging to discover ALL NTLM usage: - GPO: Network Security → Restrict NTLM → Audit NTLM authentication in this domain → Enable all - GPO: Network Security → Restrict NTLM → Audit incoming NTLM traffic → Enable auditing for all accounts - Windows Event ID 4624 (successful logon) with AuthenticationPackageName=NTLM - Windows Event ID 4776 (credential validation) for NTLM authentication attempts - Operational log: Applications and Services Log\Microsoft\Windows\NTLM

2. Dependency Mapping — Identify applications and services that REQUIRE NTLM: - Legacy IIS applications using Windows Authentication with NTLM-only configuration - SQL Server instances with NTLM-only service accounts or linked servers - RDP connections to non-domain-joined systems (Kerberos requires domain membership) - Network printers with firmware that only supports NTLM authentication - Healthcare HL7/DICOM interfaces with NTLM-only authentication modules - Manufacturing SCADA/HMI systems running Windows XP/7 embedded with no Kerberos support - Government legacy applications (COBOL-era systems with NTLM wrappers) - VPN concentrators using MSCHAPv2 (which depends on NTLMv1 primitives) - Third-party backup solutions authenticating via NTLM to file shares - Cross-domain/cross-forest trusts where Kerberos delegation isn't configured

3. GPO Enforcement — Phased NTLM restriction: - LmCompatibilityLevel: Controls which NTLM versions are accepted (0-5, where 5 = NTLMv2 only, refuse LM and NTLM) - Network Security → Restrict NTLM → NTLM authentication in this domain: Deny for domain accounts/servers - Network Security → Restrict NTLM → Outgoing NTLM traffic to remote servers: Deny all - Network Security → Restrict NTLM → Add remote server exceptions: Allowlist for systems that genuinely cannot migrate

4. Migration Path — Protocol progression: - Phase 1: NTLM → Negotiate (one-line code change in AcquireCredentialsHandle SSPI call) - Phase 2: Negotiate with Kerberos preference (Negotiate tries Kerberos first, falls back to NTLM) - Phase 3: Kerberos-only (remove NTLM fallback) - Phase 4: Certificate-based authentication (smart cards, Windows Hello for Business, FIDO2)

Industry impact: Healthcare organizations running HL7 interfaces on legacy Windows servers face authentication failures when NTLMv1 is removed. Manufacturing plants with SCADA/HMI systems on Windows Embedded cannot upgrade without replacing OT infrastructure. Government agencies with COBOL applications wrapped in NTLM authentication face multi-year migration timelines. The deprecation creates a security vs. operational continuity tension that will define enterprise IT strategy for the next 3-5 years.

MITRE ATT&CK techniques used in TL-2026-0018

credential-access

T1003 OS Credential Dumping; T1003.003 NTDS; T1040 Network Sniffing; T1110 Brute Force; T1187 Forced Authentication; T1552 Unsecured Credentials; T1556 Modify Authentication Process; T1557 Adversary-in-the-Middle; T1649 Steal or Forge Authentication Certificates

discovery

T1018 Remote System Discovery; T1046 Network Service Discovery; T1069 Permission Groups Discovery

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

execution

T1047 Windows Management Instrumentation; T1203 Exploitation for Client Execution

defense-evasion

T1078 Valid Accounts; T1134 Access Token Manipulation; T1550 Use Alternate Authentication Material; T1550.002 Pass the Hash

persistence

T1098 Account Manipulation; T1133 External Remote Services

impact

T1489 Service Stop; T1531 Account Access Removal

initial-access

T1566 Phishing

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Microsoft NTLM Deprecation

  • Microsoft — Windows
    Vulnerable versions: All versions with NTLM enabled
    Fixed in: N/A - Migration required

Remediation for Microsoft NTLM Deprecation

Immediate actions

  • Audit current NTLM usage with Event ID 4776
  • Disable NTLMv1 immediately if any detected
  • Enable Extended Protection for Authentication (EPA)
  • Document legacy applications requiring NTLM

Workarounds

  • Enable SMB signing to mitigate relay attacks
  • Implement network segmentation for legacy NTLM systems
  • Use Protected Users security group for sensitive accounts

Longer-term hardening

  • Migrate to Kerberos authentication where possible
  • Implement Azure AD/Entra ID for modern authentication
  • Use Negotiate authentication package for automatic fallback
  • Plan for Microsoft's three-phase NTLM removal timeline
  • Test applications with NTLM disabled in staging environments

Weaknesses (CWE) in Microsoft NTLM Deprecation

CWE-327, CWE-294

Timeline of Microsoft NTLM Deprecation

  • Microsoft introduces NTLM authentication in Windows NT 3.1. Challenge-response protocol designed for LAN authentication. No mutual authentication — server doesn't prove identity to client. Source: Microsoft NTLM Protocol Specification
  • Microsoft introduces NTLMv2 in Windows NT 4.0 SP4. Stronger HMAC-MD5 hashing replaces DES, adds session security and server challenge. Still lacks mutual authentication — relay attacks remain possible. Source: Microsoft [MS-NLMP]
  • Windows 2000 introduces Kerberos v5 as the default authentication protocol for Active Directory environments. NTLM retained as fallback for backward compatibility. The fallback that would persist for 25 years begins. Source: Microsoft Kerberos documentation
  • Microsoft publishes 'NTLM Blocking and You: Application Analysis and Auditing Methodologies' — first comprehensive guidance on discovering and eliminating NTLM dependencies. Introduces NTLM audit GPO settings. 15 years before deprecation. Source: https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/ntlm-blocking-and-you-application-analysis-and-auditing/ba-p/397191
  • NTLM relay attacks become the dominant Active Directory compromise technique. Tools: Responder, ntlmrelayx (Impacket), Inveigh, mitm6. Attack chain: poison LLMNR/NBT-NS → capture NTLM authentication → relay to LDAP/SMB/HTTP → domain compromise. Source: Multiple security research publications
  • PetitPotam (CVE-2021-36942) published — coerces Windows machines to authenticate via NTLM to attacker-controlled servers using EFSRPC. Combined with NTLM relay to AD CS (ESC8), enables unauthenticated domain takeover. NTLM relay goes from 'network access required' to 'unauthenticated remote.' Source: https://github.com/topotam/PetitPotam
  • Microsoft releases new NTLM pass-through authentication protections for CVE-2022-21857. Addresses trust boundary bypass where NTLM pass-through could be exploited across domain trusts. Source: https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/windows-updates-add-new-ntlm-pass-through-authentication-protections
  • CVE-2023-23397 — Microsoft Outlook NTLM credential leak via crafted email. No user interaction required — email processing triggers NTLM authentication to attacker-controlled server. Exploited by Russian GRU (APT28/Fancy Bear) against European government and military targets. NTLM's existence enables the vulnerability. Source: MSRC, Mandiant
  • Microsoft publishes migration guidance: 'In many cases, applications should be able to replace NTLM with Negotiate using a one-line change in their AcquireCredentialsHandle request to the SSPI.' Negotiate's built-in fallback to NTLM preserved during transition. Source: https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features-resources#ntlm
  • Microsoft officially deprecates ALL versions of NTLM: LANMAN, NTLMv1, NTLMv2. Announced alongside Windows 11 24H2 preview. 'Use of NTLM will continue to work in the next release but is deprecated. Calls to NTLM should be replaced by calls to Negotiate.' Source: https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features
  • NTLMv1 REMOVED in Windows 11 24H2 and Windows Server 2025. MSCHAPv2 (which uses NTLMv1 primitives and is vulnerable to the same attacks) only disabled by enabling Credential Guard. Applications depending on NTLMv1 will fail on upgraded systems. Source: Microsoft Removed Features documentation
  • Enterprise NTLM migration enters critical phase. Organizations deploying Windows 11 24H2 and Server 2025 discover NTLMv1 removal breaks: VPN concentrators using MSCHAPv2, legacy printers, SCADA/HMI systems, healthcare HL7 interfaces, and applications with hardcoded NTLM dependencies. Source: Industry reports
  • NTLMv2 sunset planning begins. Microsoft's roadmap indicates progressive NTLMv2 removal in future Windows releases. Organizations must complete dependency audits and migration to Negotiate/Kerberos before full NTLM removal. Negotiate fallback is the bridge — but the bridge has an expiration date. Source: https://aka.ms/ntlm
  • Current state: NTLMv1 removed in latest Windows. NTLMv2 deprecated, still functional but on borrowed time. Enterprise migration in progress across industries. Healthcare, manufacturing, and government face the longest migration timelines due to legacy OT and line-of-business applications. The 30-year NTLM era is ending.
  • As of 2026-05-29, this NTLM-deprecation advisory remains active and relevant: Microsoft's phase-out is mid-rollout (Phase 2 IAKerb/Local KDC due H2 2026, BlockNTLMv1SSO flips to Enforce Oct 2026), and NTLMv2 relay/pass-the-hash stays exploitable in the wild (e.g. CVE-2025-24054). It is a multi-year migration, not patched or superseded, so MONITORING fits better than the stored DORMANT.
  • Projected: NTLMv2 removal or hard-blocking in future Windows release. Organizations without completed migration will face authentication failures on upgrade. Microsoft's 'Negotiate fallback preserved during transition' has an unstated expiration date. Source: Microsoft NTLM deprecation roadmap

Sources cited for Microsoft NTLM Deprecation

Detection coverage for TL-2026-0018

As of 2026-02-02, Threadlinqs Intelligence publishes 16 detection rule(s) for TL-2026-0018 across Splunk SPL, Microsoft KQL and Sigma, covering 47 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

16 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
47 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats