Category
Active Directory & Identity
Topic
NTLM deactivation
Audience
IT administrators & AD managers
Reading time
approx. 10 minutes

Microsoft’s announcement that it will gradually phase out the NTLM authentication protocol is one of the biggest changes to the Windows security architecture in the last 20 years. For IT administrators, this means specific measures, risks and an urgent need for action.

⚠️ This article explains:

  • Why NTLM is being phased out
  • The complete timeline
  • The impact on Active Directory, printers, NAS and legacy systems
  • What administrators need to check now
  • How risks can be identified and addressed
  • How Security Audits and Pentests can help
  • How Mint Secure can help

What is NTLM and why is it being phased out?

NTLM (NT LAN Manager) is an authentication protocol from the early versions of Windows NT. It is used for:

  • Network logins
  • SMB shares
  • Authentication against servers without a Kerberos trust
  • Legacy systems and devices

The problem: NTLM is vulnerable to modern attacks:

  • Pass-the-hash attacks
  • NTLM relay attacks
  • Credential theft
  • Lateral Movement

A plaintext password is not required; a hash is sufficient. NTLM is therefore a primary attack vector for modern Ransomware attacks. 🛡️

📅 Official timeline

1

Phase 1: Deprecation and preparation (2022–2024)

Status: active / started

  • NTLM marked as deprecated
  • NTLMv1 completely removed
  • Audit mechanisms introduced
  • New security features integrated

Typical affected systems: old NAS systems, legacy printers and scanners, Linux systems running old versions of Samba, old enterprise applications.

2

Phase 2: Audit and reduction phase (2024–2026)

Status: currently active, most critical phase ⚠️

Microsoft is providing new mechanisms:

  • NTLM Audit Mode
  • NTLM Blocking Policies
  • Kerberos improvements
  • Enhanced event logs

Relevant event IDs: 4624, 4776, 8001 up to 8004. These show the source, target system, user and process. 🔍

3

Phase 3: Default deactivation (from approx. 2026)

  • NTLM disabled by default
  • Can only be enabled optionally
  • Legacy systems begin to fail
4

Phase 4: Complete removal

  • NTLM completely removed
  • Only Kerberos and modern authentication remain

Specific implications

Active Directory

  • Workgroup systems
  • Devices not joined to a domain
  • Trust issues
  • Incorrectly configured SPNs

Printers and multifunction devices

  • Scan-to-Folder fails
  • SMB authentication fails

Typically affected: older HP, Canon, Kyocera and Ricoh devices.

NAS systems

  • Older Synology systems
  • Older QNAP firmware
  • Older Windows file servers

Linux systems with Samba

Older versions of Samba use NTLM and need to be updated.

Legacy applications

  • ERP systems
  • Web applications
  • IIS applications
  • Backup systems

What administrators need to do now

1

Enable NTLM auditing

GPO setting: Network Security: Restrict NTLM: Audit NTLM authentication in this domain

2

Inventory legacy systems

Record printers, NAS systems, servers and applications.

3

Check Active Directory

Check SPNs, delegation, trusts and service accounts.

4

Test NTLM blocking in audit mode

Restrict NTLM: Deny All (first in audit mode).

5

Carry out Security Audits and Pentesting

Detect credential theft, identify attack vectors, prevent domain compromise.

Security risk: attack chain

1
The client is compromised.
2
NTLM hash is extracted.
3
Pass-the-hash attack.
4
Lateral Movement.
5
Domain controller compromise.
“A plaintext password has never been necessary with NTLM; a hash is sufficient, and that is precisely what makes the protocol one of the preferred entry points for Ransomware.”
Mint Secure GmbH

How Mint Secure supports you

As a specialist IT security service provider, we help organisations to securely migrate and harden their infrastructure.

🔎

NTLM Audit

We analyse where NTLM is being used, which systems are affected and what risks exist.

📋

AD Security Audit

We check delegations, trust relationships, Kerberos configuration, privileges and misconfigurations.

🎯

AD Penetration Testing

We simulate NTLM relay attacks, pass-the-hash and Lateral Movement to identify and eliminate attack vectors.

🖨️

Legacy System Analysis

We assess printers, NAS systems, applications and embedded devices, and develop migration strategies.

🛠️

Migration Planning

We provide support with NTLM deactivation, Kerberos migration and infrastructure modernisation.

Not sure how reliant you are on NTLM?

We’ll assess your systems together with you. Get in touch.

Conclusion

The NTLM phase-out is a fundamental security change.

Organisations that act now will avoid downtime, enhance their security and significantly reduce their attack surface.

Now is the right time to act. Mint Secure supports you every step of the way, from the initial assessment through to full migration. Talk to us.