Microsoft NTLM Retirement.

Patra, Anil 0 Reputation points
2026-08-11T08:58:29.17+00:00

Microsoft is retiring NTLM (New Technology LAN Manager), a legacy authentication protocol that has been part of Windows environments for more than 30 years.

By when Microsoft is going to stop or deprecate completely, is there any deadline for retirement? I am just interested to know last date and Did Microsoft rolled any update for NTLM after 2024.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments

2 answers

Sort by: Most helpful
  1. Brian Huynh 3,815 Reputation points Microsoft External Staff
    2026-08-12T07:39:07.48+00:00

    Hello David, thank you for posting in the Microsoft Q&A community.

    Microsoft has officially declared NTLM (including NTLMv1 and NTLMv2) as deprecated starting in Windows 11 (version 24H2) and Windows Server 2025. While NTLM remains available for backward compatibility during a transition period, future Windows releases will allow administrators to disable NTLM entirely across domain and local scopes.

    To eliminate hard dependencies on NTLM, Microsoft introduced two key architectural enhancements to the Windows authentication stack:

    1. IAKerb (Initial Authentication Protocol for Kerberos): Solves the scenario where a client computer does not have direct network connectivity (port 88) to an Active Directory Domain Controller (e.g., remote clients behind firewalls or proxies). IAKerb allows the destination server to act as a proxy, passing Kerberos authentication messages between the client and the DC wrapped inside the Negotiate/SPNEGO protocol.
    2. Local KDC: Introduces a local Kerberos Key Distribution Center built into Windows, enabling local user accounts to authenticate using Kerberos rather than falling back to NTLM for local authentication.

    Step-by-Step NTLM Audit & Migration Plan

    Phase 1: Enable NTLM Auditing Across Active Directory

    Before enforcing NTLM block policies, you must audit all incoming, outgoing, and domain-wide NTLM authentication traffic to identify legacy applications, hardcoded IP-based connections, and un-registered Service Principal Names (SPNs).

    1. Open Group Policy Management (gpmc.msc) and edit a GPO applied to Domain Controllers, Member Servers, and Clients.
    2. Navigate to:
      Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options
    3. Configure the following policies:
      • Network security: Restrict NTLM: Audit NTLM authentication in this domain -> Set to Enable all.
      • Network security: Restrict NTLM: Audit Incoming NTLM Traffic -> Set to Enable auditing for all accounts.
      • Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers -> Set to Audit all.

    Phase 2: Analyze Audit Event Logs

    Once auditing is enabled, monitor NTLM event logs to isolate NTLM callers across your infrastructure:

    • Domain Controller Event Log Path:
      Event Viewer -> Applications and Services Logs -> Microsoft -> Windows -> NTLM -> Operational
      • Event ID 8001: Audits successful domain NTLM authentications.
      • Event ID 8002 / 8003 / 8004: Audits NTLM traffic blocked or allowed by restriction rules.
    • Security Log on Servers and Clients:
      Windows Logs -> Security -> Event ID 4624 (Filter for Logon Type 3 with Authentication Package: NTLM).

    PowerShell command to query NTLM Operational Events on Domain Controllers:

    # Query NTLM Operational audit events on a Domain Controller
    Get-WinEvent -LogName "Microsoft-Windows-NTLM/Operational" -MaxEvents 100 | 
        Select-Object TimeCreated, Id, Message | 
        Format-List
    

    Phase 3: Remediation & Service Migration to Kerberos

    1. Replace IP Addresses with FQDNs: Kerberos requires Service Principal Names (SPNs), which fail when connections use raw IP addresses (e.g., \\192.168.1.50\share). Update applications and scripts to use Fully Qualified Domain Names (e.g., \\server01.corp.contoso.com\share).
    2. Register Missing SPNs: Ensure custom service accounts have correct SPNs registered:
         setspn -S HTTP/webApp.corp.contoso.com contoso\serviceAccount
      
    3. Use Negotiate SSPI Package: Update custom applications to use the Negotiate Security Support Provider (SPNEGO) instead of hardcoding NTLM. Negotiate automatically attempts Kerberos (and IAKerb) before considering NTLM.

    Phase 4: Stage NTLM Restriction & Blocking

    Once audit logs show zero unexpected NTLM traffic, enforce NTLM restrictions incrementally using Group Policy:

    1. Configure Network security: Restrict NTLM: Restrict NTLM in this domain to Audit all.
    2. Add necessary legacy servers to Network security: Restrict NTLM: Add server exceptions in this domain.
    3. Gradually shift the policy to Deny for domain accounts to domain servers and finally Deny all.

    Official Microsoft References:

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments

  2. AI answer

    2026-08-11T08:58:51.9166667+00:00

    NTLM is deprecated, not given a single final retirement date in the provided Microsoft documentation.

    What is confirmed:

    • Microsoft announced that all versions of NTLM are deprecated as of June 2024.
    • Microsoft states that NTLM will continue to work in the next release of Windows Server and the next annual release of Windows.
    • NTLMv1 is a separate milestone: it is removed starting in Windows 11, version 24H2 and Windows Server 2025.
    • Microsoft also published new NTLM auditing enhancements for Windows 11, version 24H2 and Windows Server 2025 in 2025.
    • For NTLMv1-derived credentials, Microsoft introduced auditing and enforcement changes:
      • September 2025 and later updates: Windows 11, version 24H2 clients begin rollout in Audit mode, logging Event ID 4024.
      • November 2025: rollout begins for Windows Server 2025.
      • October 2026: the default for the BlockNtlmv1SSO registry key changes from Audit (0) to Enforce (1) if that key was not already deployed.

    So, for the question about a last date for complete NTLM retirement: no final complete retirement deadline for NTLM as a whole is stated in the provided context.

    For the question about updates after 2024: yes. Microsoft rolled out and documented NTLM-related updates in 2025, including:

    • NTLM auditing enhancements for Windows 11, version 24H2 and Windows Server 2025.
    • NTLMv1 removal and NTLMv1-derived credential auditing/enforcement changes.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.