# Microsoft NTLM Deprecation - Enterprise Migration Planning Required

> Microsoft officially deprecated all versions of NTLM (LANMAN, NTLMv1, NTLMv2) in June 2024, with NTLMv1 removed in Windows 11 24H2 and Windows Server 2025. This threat analyzes the enterprise migration enforcement dimension — the operational reality of eliminating a 30-year-old authentication protocol deeply embedded in Active Directory environments, legacy applications, and critical infrastructure. NTLM's deprecation eliminates the attack surface exploited by PetitPotam, PrinterBug/SpoolSample, DropTheFlam3, NTLM relay attacks, pass-the-hash, and credential theft techniques that have been the backbone of Active Directory compromise for two decades. However, migration to Kerberos/Negotiate breaks applications with hard NTLM dependencies: legacy IIS configurations, SQL Server with NTLM-only service accounts, RDP to non-domain-joined systems, network printers with NTLM-only firmware, healthcare HL7 systems, manufacturing SCADA/HMI interfaces, and government legacy applications. Microsoft's migration path (NTLM → Negotiate → Kerberos → certificate-based auth) requires enterprise-wide dependency mapping via NTLM audit logging (Event IDs 4624/4776 with LogonType analysis), GPO enforcement (LmCompatibilityLevel, RestrictSendingNTLMTraffic, AuditNTLMInDomain), and phased rollout. The enforcement timeline creates a forcing function: organizations that don't migrate will find their authentication breaking as Windows updates remove NTLM support. This is not a vulnerability patch — it is a fundamental architecture migration affecting every Windows domain on Earth.

- **Published:** 2026-02-02T20:12:00Z
- **Last reviewed:** 2026-02-02T20:12:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0018
- **ID:** TL-2026-0018
- **Severity:** MEDIUM (CVSS 6.5)
- **Category:** ADVISORY
- **Status:** MONITORING
- **Detections:** 16 · **IOCs:** 47 (full data via the Threadlinqs MCP server — Purple tier)

## Description

NTLM (NT LAN Manager) is a family of authentication protocols introduced in 1993 with Windows NT 3.1. For 30+ years, NTLM has been the fallback authentication mechanism in Windows environments when Kerberos cannot be used — workgroup authentication, local logon, cross-domain trust scenarios, and any application that doesn't support Kerberos. Despite being superseded by Kerberos in Windows 2000, NTLM persisted because of deep backward compatibility requirements.

The security problem: NTLM is fundamentally flawed. It uses a challenge-response mechanism without mutual authentication (the server doesn't prove its identity to the client), enabling relay attacks. NTLMv1 uses weak DES-based cryptography, crackable in seconds. NTLMv2 improved hashing but retained the relay vulnerability. Pass-the-hash attacks exploit NTLM's hash-based authentication — an attacker with the NTLM hash never needs the actual password. These flaws have made NTLM the #1 target for Active Directory compromise:

- PetitPotam (CVE-2021-36942): Coerces Windows machines to authenticate to attacker-controlled servers via NTLM, enabling relay to Active Directory Certificate Services (AD CS) for domain takeover.
- PrinterBug/SpoolSample: Abuses the Print Spooler service to coerce NTLM authentication from any Windows machine to an attacker-controlled host.
- DropTheFlam3: Coerces NTLM authentication via DCOM/RPC interfaces for relay attacks.
- NTLM Relay: Forwards NTLM authentication to other services (LDAP, SMB, HTTP, MSSQL) to impersonate the victim — the canonical Active Directory attack technique.
- Pass-the-Hash: Uses stolen NTLM password hashes directly for authentication without knowing the plaintext password.
- Responder/Inveigh: Poisons LLMNR/NBT-NS/mDNS to capture NTLM authentication attempts on the local network.

Microsoft's enforcement timeline:
- June 2024: All NTLM versions deprecated (LANMAN, NTLMv1, NTLMv2). Announced alongside Windows 11 24H2.
- November 2024: NTLMv1 REMOVED in Windows 11 24H2 and Windows Server 2025. MSCHAPv2 (which uses NTLMv1 primitives) only disabled via Credential Guard.
- Future releases: Full NTLM removal planned. Negotiate fallback preserved during transition but will eventually be removed.

Enterprise migration complexity: The migration from NTLM to Kerberos/Negotiate is not a simple protocol swap. It requires:

1. NTLM Audit Phase — Enable audit logging to discover ALL NTLM usage:
   - GPO: Network Security → Restrict NTLM → Audit NTLM authentication in this domain → Enable all
   - GPO: Network Security → Restrict NTLM → Audit incoming NTLM traffic → Enable auditing for all accounts
   - Windows Event ID 4624 (successful logon) with AuthenticationPackageName=NTLM
   - Windows Event ID 4776 (credential validation) for NTLM authentication attempts
   - Operational log: Applications and Services Log\Microsoft\Windows\NTLM

2. Dependency Mapping — Identify applications and services that REQUIRE NTLM:
   - Legacy IIS applications using Windows Authentication with NTLM-only configuration
   - SQL Server instances with NTLM-only service accounts or linked servers
   - RDP connections to non-domain-joined systems (Kerberos requires domain membership)
   - Network printers with firmware that only supports NTLM authentication
   - Healthcare HL7/DICOM interfaces with NTLM-only authentication modules
   - Manufacturing SCADA/HMI systems running Windows XP/7 embedded with no Kerberos support
   - Government legacy applications (COBOL-era systems with NTLM wrappers)
   - VPN concentrators using MSCHAPv2 (which depends on NTLMv1 primitives)
   - Third-party backup solutions authenticating via NTLM to file shares
   - Cross-domain/cross-forest trusts where Kerberos delegation isn't configured

3. GPO Enforcement — Phased NTLM restriction:
   - LmCompatibilityLevel: Controls which NTLM versions are accepted (0-5, where 5 = NTLMv2 only, refuse LM and NTLM)
   - Network Security → Restrict NTLM → NTLM authentication in this domain: Deny for domain accounts/servers
   - Network Security → Restrict NTLM → Outgoing NTLM traffic to remote servers: Deny all
   - Network Security → Restrict NTLM → Add remote server exceptions: Allowlist for systems that genuinely cannot migrate

4. Migration Path — Protocol progression:
   - Phase 1: NTLM → Negotiate (one-line code change in AcquireCredentialsHandle SSPI call)
   - Phase 2: Negotiate with Kerberos preference (Negotiate tries Kerberos first, falls back to NTLM)
   - Phase 3: Kerberos-only (remove NTLM fallback)
   - Phase 4: Certificate-based authentication (smart cards, Windows Hello for Business, FIDO2)

Industry impact: Healthcare organizations running HL7 interfaces on legacy Windows servers face authentication failures when NTLMv1 is removed. Manufacturing plants with SCADA/HMI systems on Windows Embedded cannot upgrade without replacing OT infrastructure. Government agencies with COBOL applications wrapped in NTLM authentication face multi-year migration timelines. The deprecation creates a security vs. operational continuity tension that will define enterprise IT strategy for the next 3-5 years.

## MITRE ATT&CK

- T1649 Steal or Forge Authentication Certificates
- T1003.003 NTDS
- T1550.002 Pass the Hash
- T1557 Adversary-in-the-Middle
- T1187 Forced Authentication
- T1003 OS Credential Dumping
- T1110 Brute Force
- T1550 Use Alternate Authentication Material
- T1021 Remote Services
- T1210 Exploitation of Remote Services
- T1556 Modify Authentication Process
- T1098 Account Manipulation
- T1078 Valid Accounts
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1566 Phishing
- T1203 Exploitation for Client Execution
- T1531 Account Access Removal
- T1133 External Remote Services
- T1552 Unsecured Credentials
- T1040 Network Sniffing
- T1685 Disable or Modify Tools
- T1134 Access Token Manipulation
- T1069 Permission Groups Discovery
- T1047 Windows Management Instrumentation
- T1489 Service Stop

## Sources

- [Microsoft — NTLM Overview in Windows Server](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview)
- [Microsoft — Deprecated Features in Windows Client (NTLM)](https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features)
- [Microsoft — NTLM Migration Guidance](https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features-resources#ntlm)
- [Microsoft — Restrict NTLM Audit GPO](https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-audit-ntlm-authentication-in-this-domain)
- [Microsoft — NTLM Blocking and You: Auditing Methodologies](https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/ntlm-blocking-and-you-application-analysis-and-auditing/ba-p/397191)
- [Microsoft — NTLM Protocol Specification MS-NLMP](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nlmp/b38c36ed-2804-4868-a9ff-8dd3182128e4)
- [Microsoft — Kerberos Troubleshooting Guide](https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/kerberos-authentication-troubleshooting-guidance)
- [Microsoft NTLM Deprecation Tracker](https://aka.ms/ntlm)
- [PetitPotam — NTLM Relay via EFSRPC](https://github.com/topotam/PetitPotam)
- [Responder — LLMNR/NBT-NS Poisoner](https://github.com/lgandx/Responder)
- [Impacket — ntlmrelayx Relay Tool](https://github.com/fortra/impacket)
- [Microsoft — Windows 11 24H2 Removed Features](https://learn.microsoft.com/en-us/windows/whats-new/removed-features)
- [Microsoft — Extended Protection for Authentication](https://learn.microsoft.com/en-us/dotnet/framework/wcf/feature-details/extended-protection-for-authentication-overview)
- [Microsoft — CVE-2022-21857 NTLM Pass-Through Protections](https://learn.microsoft.com/en-us/troubleshoot/windows-server/windows-security/windows-updates-add-new-ntlm-pass-through-authentication-protections)
- [MITRE ATT&CK — Forced Authentication (T1187)](https://attack.mitre.org/techniques/T1187/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0018
