Microsoft's Windows 11: Changes to Authentication and Upgrades

1 min read
Source: BleepingComputer
Microsoft's Windows 11: Changes to Authentication and Upgrades
Photo: BleepingComputer
TL;DR Summary

Microsoft plans to phase out the NTLM authentication protocol in Windows 11, as it has been extensively exploited by threat actors in attacks such as NTLM relay attacks and pass-the-hash attacks. Kerberos has replaced NTLM as the default authentication protocol for domain-connected devices on Windows. Microsoft is working on two new Kerberos features, IAKerb and Local KDC, to enhance its use and address challenges leading to Kerberos fallback to NTLM. Additionally, Microsoft intends to expand NTLM management controls to provide administrators with more flexibility in monitoring and restricting NTLM usage. The company will disable NTLM in Windows 11 once it determines it is safe to do so, but customers will have the option to reenable it for compatibility reasons.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

77%

507119 words

Want the full story? Read the original article

Read on BleepingComputer