Microsoft announced it will disable NTLM by default in future Windows releases, accelerating the retirement of the 30-year-old authentication protocol in favor of more secure, modern alternatives such as Kerberos and phishing-resistant, passwordless methods. NTLM remains widely used as a fallback when Kerberos is unavailable, but it relies on weak cryptography and is frequently abused for NTLM relay and pass-the-hash activity that can enable privilege escalation and domain compromise; the announcement highlights long-standing exploitation paths and coercion techniques associated with relay scenarios (e.g., PetitPotam, ShadowCoerce, DFSCoerce, RemotePotato0).
Separately, Microsoft is moving Exchange Online toward deprecating SMTP AUTH Basic Authentication for all tenants, citing persistent abuse of basic-auth SMTP for password spraying/brute force and subsequent account takeover used to send phishing and spam. The change targets legacy workflows (devices, scripts, and third-party tools) that keep basic auth enabled and often bypass modern controls like MFA and Conditional Access; the referenced timeline indicates SMTP AUTH Basic Authentication remains available until December 2026 to allow organizations to identify dependencies and migrate to stronger authentication methods.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Microsoft said the second phase of the NTLM transition is planned for the second half of 2026 and will focus on reducing fallback to NTLM, including Local KDC preview support and Windows component updates that prioritize Kerberos.
As Phase 1 of the NTLM transition, Microsoft made enhanced auditing available to help organizations identify where NTLM is still used and what triggers fallback to the protocol.
Microsoft said future major Windows releases will block network NTLM authentication by default as part of a phased transition toward Kerberos and a secure-by-default posture.
Microsoft said that after December 2026, SMTP AUTH Basic Authentication will be disabled by default for existing Exchange Online tenants, with temporary re-enablement available during migration. For new tenants created after that point, SMTP AUTH Basic Authentication will be unavailable by default and OAuth-based modern authentication will be the supported method.
Microsoft updated its Exchange Online timeline to keep SMTP AUTH Basic Authentication unchanged until December 2026, despite describing it as an outdated and frequently abused sign-in method.
Microsoft formally deprecated NTLM, reinforcing that the legacy protocol should be phased out because of its longstanding security weaknesses and abuse in enterprise attacks.
Microsoft previously signaled that NTLM would be retired, marking the start of its public move away from the legacy authentication protocol in favor of more secure alternatives.
In the final phase of the rollout, a future major Windows release will disable network NTLM authentication by default, while still allowing administrators to explicitly re-enable it through policy controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.