Blog

NTLM Security in a Cloud-First World: Why It’s Time to Let Go

Config hardening
Misconfigs
ntlm-security-dilemma

In the modern Microsoft environment, NTLM (“NT Lan Manager”) is a security threat you should keep an eye on. Especially when it’s about the cloud environment, Microsoft warns you to deny it before accessing Azure resources.

However, things have not always been that way.

If you have been involved in Microsoft IT Systems for a long time, you will be familiar with the NTLM authentication protocol. In fact, NT LAN Manager was first introduced as far back as 1993 with the introduction of Windows NT 3.1. In 1994, it was updated to NTLM v2 as part of the NT 4.0 service pack 4 release with some security improvements to prevent replay style attacks.

Given that NTLM is a legacy protocol, Microsoft does not recommend it to be used in applications. Kerboros protocol should be used instead. Despite this, Remedio's found that as of 2021, NTLM is still widely used within enterprises. The main reason? Backwards compatibility with older applications.

That’s a bad excuse of course. Sometimes you need to open a window, but it's no reason make a hole in the wall.

Why NTLM Poses Serious Risks

The good news is that with some knowledge of Group Policy, you can get a good control over it. The bad news is that it’s not so obvious: different versions of Windows have different behaviors about the protocol.

So what’s so dangerous about NTLM anyway?

A protocol of this age will have a number of security risks. For example:

NTLM v1 uses the DES block cipher algorithm using an MD4 hash. In 2012, it was proven it can be broken by brute force mainly due to the fact that a full 128-bit key is not used.

NTLM v2 uses a stronger hash algorithm and encryption than v1. Still, it can be easily exploited using either Pass The Hash (see our article on this) or Man in the Middle hacking technique.

These NTLM weaknesses are used by hackers to breach Windows machines, both as the entry point and to move laterally.

Usage of NTLM in an organization could have a major impact. You should strive to block NTLM completely – and until you achieve that, you must monitor its usage on all your servers and endpoints, all the time.

why-block-ntlm-security-needs

Addressing Business Needs Without Compromising Security

This is where Remedio can help. Our solution monitors all endpoints and servers in an organization, and detects misconfigurations.

This includes NTLM misconfiguration such as:

  • Detecting and alerting
    • Identifying which endpoints and servers are configured to use NTLM
    • Alerting when an endpoint has made a configuration changes from Kerboros to NTLM (often the sign of a suspicious attack vector).
  • Validating usage
    • Confirming that NTLM rules have been correctly applied via Group Policy for all different Windows OS versions.
    • Monitoring the network traffic to assure that NTLM is not used for accessing Azure resources from the on-prem network.

SecOps and IT Admins now have total visibility of configuration security risks in their organization. Critically, with the help of the Remedio, the misconfiguration can be fixed immediately and without any interruption.


Discover how Remedio can help you gain visibility into your endpoint risk  posture »

FAQ

What is NTLM, and why is it considered a security risk today?
NTLM (NT LAN Manager) is a legacy Microsoft authentication protocol designed for older Windows environments. While it provides backward compatibility, it lacks the security protections of modern authentication methods such as Kerberos. NTLM remains vulnerable to attacks including Pass-the-Hash, relay attacks, and credential theft, making it a common target for attackers seeking lateral movement within enterprise networks.
Why is NTLM still widely used if Microsoft recommends moving away from it?
Many organizations continue using NTLM because older applications, legacy operating systems, and business-critical services still depend on it. Eliminating NTLM without understanding these dependencies can disrupt operations, so many enterprises must first identify where NTLM is in use before safely transitioning to more secure authentication methods.
What are the biggest security risks associated with NTLM?
NTLM can expose organizations to credential relay attacks, Pass-the-Hash attacks, and man-in-the-middle attacks. Once attackers obtain or relay NTLM credentials, they can often authenticate to additional systems without knowing the user's password, enabling privilege escalation and lateral movement across Windows environments.
How can organizations identify where NTLM is still being used?
The most effective approach is to continuously monitor authentication traffic across endpoints and servers. Organizations should identify systems configured to use NTLM, detect configuration changes that re-enable the protocol, validate Group Policy settings, and monitor for NTLM authentication attempts against cloud services such as Azure.
Can organizations disable NTLM immediately?
Not always. While Microsoft's long-term recommendation is to eliminate NTLM where possible, many environments contain legacy systems that still require it. A phased approach that inventories dependencies, validates configurations, and gradually replaces NTLM with Kerberos or other modern authentication mechanisms helps reduce security risk without causing unnecessary service interruptions.
What role does Group Policy play in reducing NTLM risk?
Group Policy allows administrators to control how NTLM is used across Windows devices. Properly configured policies can restrict or block NTLM authentication, enforce consistent security settings, and help ensure devices remain aligned with organizational security standards. Regular validation is important because policy drift or configuration changes can unintentionally reintroduce NTLM usage.
How does continuous configuration monitoring improve NTLM security?
Continuous monitoring helps detect when devices are configured to use NTLM, identifies unauthorized configuration changes, and verifies that security policies remain correctly applied over time. This enables security teams to detect misconfigurations quickly and remediate them before attackers can exploit them.
What should organizations prioritize after reducing their dependence on NTLM?
After minimizing NTLM usage, organizations should continuously validate authentication policies, monitor for configuration drift, replace remaining legacy dependencies, and maintain ongoing visibility into endpoint and server configurations. Authentication security is not a one-time migration but an ongoing operational process that requires continuous verification.

About Author

Mor Bikovsky

Mor Bikovsky

Chief Business Officer

Mor draws on more than a decade of cyber and business strategy experience to lead Remedio's Business Strategy. Before joining Remedio, Mor led Global BD efforts for Claroty and filled a variety of key technology roles for Israel's intelligence services.

Fix Misconfigurations Without Fear

Automate configuration security while keeping full control.

Book a Demo