Event details

NTLM (New Technology LAN Manager) in Windows 11 is being phased out in favor of more secure protocols like Kerberos. Learn the history of NTLM and the associated security risks. Explore how auditing can expose legacy dependencies in storage traffic, then find out how IAKerb, Local KDC, and auto-redirect can fill Kerberos gaps so that you feel confident and prepared ahead of NTLM disablement in Windows.

Speakers: Mariam Gewida & Steve Syfuhs

 

This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, click Attend for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event.

Heather_Poulsen
Updated Feb 26, 2026

12 Comments

  • When can we expect CSP or settings catalog Policies in Intune to elmininate NTLM and other active directory hardening? It's really frustrating to write scripts for all registry keys and it's more prone to error.

    • Steve_Syfuhs's avatar
      Steve_Syfuhs
      Icon for Microsoft rankMicrosoft

      Existing NTLM disable sent policies are already available in GP and Intune. Can you clarify what more you're expecting to see?

  • Any chance this will be back ported to at least Windows Server 2022? I mean it's still supported for another five years at least.

    • Steve_Syfuhs's avatar
      Steve_Syfuhs
      Icon for Microsoft rankMicrosoft

      No plan to backport to 2022 but if the demand is there that justifies the cost of doing so we would certainly consider it.

  • Welcome to “Eliminating NTLM in Windows” at Microsoft Technical Takeoff. Q&A is open now and throughout the week. Please post any questions or feedback here in the Comments. [Note: If your organization’s policies prevent you from seeing the video on this page, you can also tune in on LinkedIn.]

    • AWTG's avatar
      AWTG
      Occasional Reader

      Is it NTLMv1 that will be deprecated later this year or NTLMv2 also? It's not quite clear.

      • Heather_Poulsen's avatar
        Heather_Poulsen
        Icon for Community Manager rankCommunity Manager

        AWTG​ - (From Steve_Syfuhs​) - NTLMv1 has already been deprecated for more than a decade. It was deprecated when we introduced Credential Guard in Windows 10. As such, we're talking NTLMv2.

  • Hi, we have seen recommendations about eliminating NTLM in hardening NTLM, but having issues with Defender for Endpoint were it's not checking the correct keys to remediate this issue. Is this issue known within the Defender experts?