Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Moves Closer to Disabling NTLM

Microsoft Moves Closer to Disabling NTLM

Posted on February 2, 2026February 2, 2026 By CWS

The New Know-how LAN Supervisor (NTLM) authentication protocol is nearing its finish and can not be enabled within the subsequent model of Home windows Server, Microsoft says.

The legacy protocol has been current in Home windows for over three many years, however it’s prone to varied sorts of assaults, together with relay, replay, and man-in-the-middle assaults, and Microsoft deprecated NTLM in favor of stronger, Kerberos-based alternate options.

Though it not receives updates or enhancements, NTLM remains to be used, exposing organizations to assaults because of the lack of authentication, weak cryptography, and restricted diagnostic information.

“Regardless of its deprecated standing, NTLM continues to be prevalent in environments the place fashionable protocols, corresponding to Kerberos, are usually not possible because of legacy dependencies, community limitations, or ingrained software logic,” Microsoft notes.

The tech large’s objective is to fully take away NTLM, and it’s taking a three-phase strategy to disable it by default on Home windows Server and Home windows purchasers.

Now, organizations can use the improved NTLM auditing options of Home windows Server 2025 and Home windows 11, variations 24H2 and later, to know the place and why the protocol remains to be used of their environments.Commercial. Scroll to proceed studying.

The subsequent section will contain overcoming hurdles confronted when eliminating NTLM, associated to area controllers, native account authentication, and the hardcoded NTLM utilization. The options shall be launched within the second half of the yr, for Home windows Server 2025 or Home windows 11, model 24H2 and later.

Directors may have IAKerb and native Key Distribution Middle (KDC) (pre-release) for Kerberos authentication with out NTLM fallback and Microsoft will replace core Home windows options to barter Kerberos first, thus lowering NTLM’s utilization.

The subsequent main releases of Home windows Server and related Home windows shopper will nonetheless have NTLM, however it will likely be disabled by default and would require express re-enablement via new coverage controls. Constructed-in assist for NTLM solely circumstances may also be included.

“Disabling NTLM by default doesn’t imply fully eradicating NTLM from Home windows but. As a substitute, it signifies that Home windows shall be delivered in a secure-by-default state the place community NTLM authentication is blocked and not used robotically,” Microsoft explains.

In accordance with the tech large, disabling NTLM represents a significant step towards a passwordless, phishing-resistant future, however requires that organizations start or speed up their NTLM discount efforts via audits, dependency mapping, migration to Kerberos, NTLM-off configurations testing, and enabling Kerberos upgrades as they develop into out there.

Associated: Microsoft Patches Workplace Zero-Day Doubtless Exploited in Focused Assaults

Associated: New ‘Reprompt’ Assault Silently Siphons Microsoft Copilot Knowledge

Associated: Microsoft Names New Working CISOs in Strategic Transfer to Strengthen Cyberdefense

Associated: Microsoft Unveils Safety Enhancements for Id, Protection, Compliance

Security Week News Tags:Closer, Disabling, Microsoft, Moves, NTLM

Post navigation

Previous Post: Japan, Britain to Boost Cybersecurity and Critical Minerals Cooperation as China’s Influence Grows
Next Post: Over 1,400 MongoDB Databases Ransacked by Threat Actor

Related Posts

CISA Analyzes Malware From Ivanti EPMM Intrusions CISA Analyzes Malware From Ivanti EPMM Intrusions Security Week News
Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day Security Week News
Ad and PR Giant Dentsu Says Hackers Stole Merkle Data Ad and PR Giant Dentsu Says Hackers Stole Merkle Data Security Week News
BreachRx Lands  Million as Investors Bet on Breach-Workflow Software BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software Security Week News
CISA Warns of Two Exploited TeleMessage Vulnerabilities  CISA Warns of Two Exploited TeleMessage Vulnerabilities  Security Week News
WhatsApp Boosts Account Security for At-Risk Individuals WhatsApp Boosts Account Security for At-Risk Individuals Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News