Microsoft plans to disable NTLM authentication protocol in Win11
CTOnews.com October 12 news, Microsoft announced a new round of transition plans in a press release today, abandoning NTLM authentication and allowing more enterprises and users to transition to Kerberos.
Microsoft says Kerberos provides better security and is more extensible than NTLM, and is now the default protocol of choice in Windows.
Although enterprises can turn off NTLM authentication, but those hardwired applications and services may encounter problems, two authentication features have been introduced for Microsoft.
One is Initial and Pass Through Authentication Using Kerberos (IAKerb), which allows "clients without the sight of a domain controller to authenticate through a server with a line of sight."
The other is Kerberos's Local key Distribution Center (KDC), which adds authentication support for local accounts. With the promotion of the above two functions, Kerberos will become the only Windows authentication protocol.
CTOnews.com Note: NTLM is a Microsoft proprietary protocol that authenticates users and computers based on the challenge / response model. NTLM (NT LanMan) is the authentication method used by all Windows NT series products. Like its predecessor, LanMan, NTLM uses a challenge / response model to verify the identity of the client without sending passwords or hashing passwords on the network.