Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 839

NTLM Authentication

Reviewed byCybersecurity entrepreneur & security researcher

What is NTLM Authentication?

NTLM AuthenticationA legacy Windows challenge-response authentication protocol that proves a user's identity from a stored password hash, now considered weak by modern standards.


NTLM (NT LAN Manager) is a family of Microsoft authentication protocols predating Kerberos in Windows networks. It uses a challenge-response handshake: the server sends a random nonce, and the client returns a response computed from the user's NT hash, so the password itself never crosses the wire. NTLMv1 relied on weak DES-based computation; NTLMv2 uses an HMAC-MD5 response, but neither binds the exchange to the target service, which is the root of its danger.

Attacks and deprecation

Because the response only proves knowledge of the hash, NTLM is exposed to pass-the-hash (replaying a stolen hash without cracking it), offline cracking of captured hashes, and above all NTLM relay: an attacker who coerces a victim to authenticate forwards that authentication to a third service. CVE-2019-1040 ("Drop the MIC") let attackers strip the Message Integrity Code and remove signing during relay. Coercion primitives such as PetitPotam (CVE-2021-36942, patched August 2021) trigger unauthenticated machine authentication that, when relayed to an AD CS web-enrollment endpoint (ESC8, advisory ADV210003), yields a certificate for a domain controller and full domain takeover.

Microsoft began formally deprecating NTLM in 2024, steering Windows 11 toward Kerberos with IAKerb and a local KDC. Defences: enforce SMB and LDAP signing, enable Extended Protection for Authentication (channel binding), restrict outbound NTLM via Group Policy, and prefer Kerberos-only configurations.

flowchart TD
  C[Client] -->|1 NEGOTIATE| S[Server]
  S -->|2 CHALLENGE nonce| C
  C -->|3 RESPONSE from NT hash| S
  S -->|4 forward to domain controller| DC[Domain controller]
  DC -->|5 verify hash| S
  S -->|6 access granted| C

● Examples

  1. 01

    An attacker capturing NTLMv2 hashes via a rogue SMB server and cracking them offline with hashcat.

  2. 02

    NTLM relay through an unsigned SMB session to authenticate to a domain controller.

● Frequently asked questions

What is NTLM Authentication?

A legacy Windows challenge-response authentication protocol that proves a user's identity from a stored password hash, now considered weak by modern standards. It belongs to the Identity & Access category of cybersecurity.

What does NTLM Authentication mean?

A legacy Windows challenge-response authentication protocol that proves a user's identity from a stored password hash, now considered weak by modern standards.

How do you defend against NTLM Authentication?

Defences for NTLM Authentication typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for NTLM Authentication?

Common alternative names include: NTLM, NT LAN Manager.

● Related terms

● See also