Free tools Windows power users keep installed
One-click scans. No signup required.
PetitPotam can induce a Windows system to authenticate, and an attacker may try to relay that authentication to another service. The danger is not automatic: the relay succeeds only if the target accepts it without effective protections. Microsoft identifies AD CS web enrollment as a significant risk when those protections are missing. Available Microsoft guidance does not establish that PetitPotam is more dangerous than every other relay technique.
What an NTLM relay attack does
NTLM authentication uses a challenge-and-response exchange. In a relay attack, an attacker forwards that exchange to a target service so the target authenticates the relayed client. The attacker is not necessarily cracking a password or learning the password from the exchange.
A key weakness is that NTLM cannot verify the server’s identity in the way Kerberos can. Microsoft explains this in its Learn guidance, Protect SMB traffic from interception. If a service does not enforce suitable protections, it may accept an authentication exchange forwarded by an attacker. That does not make every NTLM connection exploitable: the receiving service and its configuration determine whether the relay works.
Where PetitPotam fits in the attack chain
PetitPotam is a way to induce authentication, not a synonym for the whole relay attack. Microsoft describes EFS-RPC activity as a preliminary step. The attacker then attempts to forward the resulting authentication to a service that may accept it.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Induce authentication: PetitPotam uses behavior related to the Windows Encrypting File System Remote Protocol (EFS-RPC) to prompt a Windows machine to authenticate.
- Attempt to relay it: The attacker forwards the authentication exchange to a target service.
- Rely on the target’s configuration: The target must accept the relayed authentication without an effective defense. Inducing authentication alone does not prove that the relay succeeded.
Microsoft Support’s KB5005413, Mitigating NTLM Relay Attacks on Active Directory Certificate Services (AD CS), calls PetitPotam “a classic NTLM Relay Attack” and points to previously documented mitigations. The distinction matters: the coercion step creates an opportunity, while the target service’s protections determine whether that opportunity becomes access.
Why AD CS web enrollment can make the chain serious
Active Directory Certificate Services (AD CS) issues and manages certificates in Windows environments. Microsoft specifically identifies two web-based enrollment services as potentially vulnerable when NTLM relay protections are not configured:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Certificate Authority Web Enrollment
- Certificate Enrollment Web Service
If an attacker can relay authentication to a vulnerable enrollment endpoint, the potential impact can extend beyond the initial authentication attempt. The exact outcome depends on the environment, service configuration, and what the authenticated account is allowed to do; the available Microsoft guidance does not make every deployment or account equally vulnerable.
The phrase “most dangerous” implies a ranking that the cited Microsoft sources do not provide. They establish a serious, configuration-dependent attack path, not that PetitPotam is objectively more dangerous than all other ways to coerce or relay authentication.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Which protection applies to which service?
| Service or exposure | Relevant protection or action | What to verify |
|---|---|---|
| AD CS Certificate Authority Web Enrollment and Certificate Enrollment Web Service | Microsoft recommends Extended Protection for Authentication (EPA); KB5005413 calls the Required setting the more secure, recommended option. Microsoft also recommends disabling HTTP on AD CS servers. | Check EPA on each applicable enrollment service, the HTTP configuration, and the version-specific implementation instructions. Follow the Certificate Enrollment Web Service configuration guidance where applicable. |
| SMB | SMB signing helps mitigate relay over SMB. Microsoft also describes protections in SMB 3.0 and later; SMB 1.0 lacks security features available in later versions. | Check signing and SMB version against Microsoft’s current SMB hardening guidance. SMB signing does not secure an HTTP-based AD CS enrollment endpoint. |
| LDAP | Microsoft reports that LDAP channel binding was enabled by default in Windows Server 2025. | Verify the server version and effective channel-binding configuration; do not infer the setting from a different version or an upgrade history. |
| Incoming NTLM to AD CS servers | Microsoft recommends considering restrictions on incoming NTLM. | Assess legacy dependencies before enforcement so that required authentication flows are not unexpectedly disrupted. |
How to prioritize defensive checks
- Inventory exposed enrollment services. Identify whether Certificate Authority Web Enrollment or Certificate Enrollment Web Service is installed and reachable, and record the server version and configuration.
- Configure EPA on AD CS web enrollment. Apply Microsoft’s current, version-specific instructions to each applicable service. For the EPA setting, Microsoft identifies Required as the more secure recommended choice.
- Disable HTTP on AD CS servers. Follow Microsoft’s guidance for the services in use, including any applicable Certificate Enrollment Web Service configuration.
- Harden other relay targets separately. Use SMB signing where appropriate, and review LDAP channel binding and other protections for the deployed service. A control for one protocol does not substitute for configuring another.
- Evaluate NTLM restrictions. Consider limiting incoming NTLM to AD CS servers, but first identify and test legacy dependencies.
- Confirm effective settings. Verify actual server versions and live configuration rather than assuming that a documented default applies to every installation.
Defaults depend on product version
Microsoft’s 2024 documentation reports EPA enabled by default for Exchange Server 2019 CU14 and for AD CS and LDAP in Windows Server 2025. The same documentation describes the Windows Server 2025 EPA default as “Enabled – When Supported”; it also reports LDAP channel binding enabled by default in Windows Server 2025. These are version-specific defaults, not evidence that older systems or every upgraded server have the same effective settings. Check each deployed product’s configuration.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Detection can help, but does not replace prevention
Microsoft’s 2021 Defender for Identity post says that version 2.158 and later triggers an alert when an attacker attempts to exploit EFS-RPC against a domain controller, describing this as the preliminary step of PetitPotam. Treat that alert as a detection opportunity: it may help surface attempted coercion, but it does not configure or protect an AD CS, SMB, or other relay target.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

