NT LAN Manager, an older Windows challenge-response protocol available through Microsoft Entra Domain Services. Mounting Azure Files over SMB with a key relies on NTLMv2, so permitting Kerberos alone breaks such mounts.
Also called NT LAN Manager.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305SC-500AZ-900SC-900SC-200AZ-802MD-102ALZ
Each book explains NTLM in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Entra Domain Services
Domain hosted and managed in Azure that provides Kerberos, NTLM and LDAP. Its contents come from Entra ID, so no connection to on-premises is required.
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- SMB
Protocol for Windows file shares, used by Azure Files and supporting authentication based on identity.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Kerberos
Authentication protocol based on tickets, native to Windows and Active Directory. Azure Files, Entra Domain Services and application proxy KCD all support it.
Related terms
- Audit Credential Validation
Logs credential checks during user sign-in, such as a domain controller handling NTLM authentication; part of advanced auditing.
- Credential Guard
Uses virtualisation-based security to isolate Kerberos TGTs and NTLM hashes. Windows Server 2025 enables it automatically on domain-joined member servers (not DCs), which breaks live migration relying on CredSSP.
- IWA
Sign-in method where domain users access apps with their existing Windows credentials over Kerberos or NTLM. To expose such apps outside the network, Microsoft Entra application proxy can publish them using Kerberos Constrained Delegation.
- Negotiate
Picks Kerberos where it can and drops back to NTLM only otherwise. Apps should call this Windows security package rather than NTLM itself.
- NTLMv1
The first NTLM version. It no longer ships with Windows 11 24H2 or Windows Server 2025, Credential Guard blocks it, and the version a logon relied on is recorded in event 4624.
- Protected Users
Members get fixed protections: four-hour TGTs, no delegation, no Digest, CredSSP or NTLM, and no RC4 or DES during Kerberos pre-authentication. Keep computer and service accounts out of this global group.
- SMB authentication rate limiter
Introduced in Windows Server 2025 to slow password guessing: after every failed NTLM or PKU2U sign-in to an SMB server, it waits a set time, two seconds unless changed.
- SMB NTLM blocking
A Windows Server 2025 SMB client option that prevents NTLM on outgoing SMB connections so that Kerberos has to be used.