Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protecting an environment from NTLM attacks does not usually start with turning NTLM off everywhere. Patch Outlook and Windows, find where NTLM is still in use, harden services that can be targeted by relay attacks, and migrate compatible dependencies before enforcing broader restrictions. This staged approach reduces exposure while limiting the risk of breaking applications, services, or domain workflows that still rely on NTLM.

What NTLM risk are you trying to reduce?

NTLM is a legacy Windows authentication protocol. Microsoft prefers Kerberos version 5 for Active Directory, but NTLM remains in use in workgroups, local logons, and some application scenarios. Its continued presence can create opportunities for relay attacks, in which an attacker uses authentication activity against a service that does not adequately protect the exchange.

There is no single setting that safely removes every NTLM risk from every Windows environment. The right controls depend on which systems and applications still use the protocol. Treat NTLM reduction as a staged security program: first address known exposure, then discover dependencies, protect high-value accounts and relay targets, and finally restrict remaining NTLM use where testing shows it is safe.

What should you do first?

Install the relevant security updates

Install current security updates for Outlook and Windows on supported systems. Microsoft’s guidance for CVE-2023-23397 says the Outlook update is required regardless of where the organization hosts its mail or whether it supports NTLM. Do not treat disabling NTLM as a substitute for installing that update.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Check your platform’s built-in protections

Windows Server 2025 enables Extended Protection for Authentication (EPA) by default for Active Directory Certificate Services (AD CS) and Exchange Server, and enables LDAP channel binding by default, according to Microsoft’s published roadmap. Administrators using older supported versions may need to enable these protections manually, following procedures appropriate to each version.

How can you find where NTLM is still being used?

Audit before imposing broad restrictions. Enhanced NTLM auditing on Windows 11, version 24H2, and Windows Server 2025 can identify the account involved, the reason for NTLM activity, and its location. Use those findings to build a dependency inventory rather than treating an audit event as an automatic justification for an exception.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

For each dependency, record the application or service, the host, the account, and the protocol involved. Identify who owns it and whether it can use Kerberos or another modern authentication method. This record lets you distinguish a necessary, temporary exception from an unexamined source of continued exposure.

How should you reduce the risk in stages?

Protect privileged identities

Where compatibility permits, place high-value accounts in the Protected Users security group. Microsoft notes that this prevents NTLM for members. Because some applications require NTLM, test affected workflows and accounts before applying the protection broadly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Constrain SMB and other network paths

Block outbound TCP port 445 where it is not needed, and restrict inbound ports 135 and 445 to controlled allowlists. These network controls can reduce unnecessary paths to SMB and related services; they do not replace application patching or authentication hardening.

Windows Server 2025 and Windows 11, version 24H2, also support an SMB-specific NTLM block. Consider this control when you need to restrict NTLM for SMB without applying an environment-wide NTLM restriction. Validate required SMB workflows and exceptions before enforcing it.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Harden services that may be relay targets

Enable EPA for Exchange and AD CS, and LDAP channel binding where supported. On older systems, use Microsoft’s version-specific procedures: availability and configuration can differ by Windows and service version. These protections strengthen the relevant authentication paths; they do not mean every other NTLM dependency has been removed.

Migrate dependencies, then enforce broader restrictions

Move compatible applications and services to Kerberos or another modern authentication method. Test the replacement in the workflows that depend on it, resolve failures, and document any remaining exception. Then apply restrictive NTLM Group Policy in stages, rather than assuming a broad setting will be safe across all systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Keep a rollback path for legacy dependencies: document the affected service, the restriction that changed, the owner responsible for the exception, and how to restore service if testing or rollout reveals a breakage. Revisit exceptions as applications are migrated so they do not become permanent by default.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is staged reduction safer than disabling NTLM immediately?

Consideration Staged NTLM reduction Immediate broad disablement
Dependency visibility Auditing and inventory can reveal which accounts, applications, hosts, and protocols still depend on NTLM. May expose dependencies only after authentication or application failures occur.
Outage risk Restrictions can be tested and applied selectively as dependencies are migrated. Can disrupt workgroup, local-logon, or application scenarios that still require NTLM.
Relay protection Lets administrators harden exposed services and constrain network paths while migration proceeds. Reduces NTLM use broadly, but the change itself does not establish that services are patched or correctly hardened.
Privileged-account coverage Protected Users can be applied to high-value identities where compatible. A broad restriction may affect privileged and non-privileged workflows alike.
Audit and rollback Provides a basis for documented exceptions, staged enforcement, and recovery planning. Can make it harder to identify which dependency caused a failure unless discovery and rollback planning happened first.

Microsoft emphasizes auditing and dependency discovery before selective restriction. For most environments, that makes staged reduction the more controllable path; immediate broad disablement should be considered only when dependencies and operational impact are understood.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.