Skip to content
Microsoft Plans to Disable NTLM by Default in Future Windows Versions

Microsoft Plans to Disable NTLM by Default in Future Windows Versions

Written By Anoop C Nair
Last Updated March 9, 2026
Posted In Windows
SHARE

Key Takeaways

  • Disable NTLM by Default in Future Windows Versions
  • NTLM will be disabled by default in most scenarios in upcoming versions of Microsoft Windows.
  • Changes are expected to begin rolling out in the second half of 2026.
  • Some Windows components that are currently hard-coded to use NTLM will be updated to support Negotiate authentication, allowing the use of Kerberos.
  • Microsoft will introduce new NTLM blocking policies to help organizations identify and control NTLM

In this post we are discussing on Microsoft Plans to Disable NTLM by Default in Future Windows Versions. During a security session, Maryam Gawita explained about Disable NTLM by Default in Future Windows Versions. So, let understand from that Microsoft have the plans to strengthen authentication security in future versions of Windows by gradually reducing the use of NTLM, an authentication protocol that has been widely used across Windows environments for many years.

Table of Contents

Microsoft Plans to Disable NTLM by Default in Future Windows Versions

Microsoft is working on several updates that will reduce NTLM dependency and encourage the use of stronger authentication methods such as Kerberos. These changes are expected to improve security while helping organizations transition to more modern authentication practices.

According to the roadmap, new updates planned for the second half of 2026 will introduce improvements such as enhanced Local KDC capabilities and updates to Windows components that currently rely on NTLM. In future versions of Windows Server and Windows client systems, NTLM is expected to be disabled by default in most scenarios.

Roadmap for NTLM Changes

As part of the roadmap, Microsoft plans to introduce improvements like Local KDC support and updates to Windows components that are currently hard-coded to use NTLM. Some first-party Windows applications will be updated to use Negotiate authentication, allowing systems to use stronger protocols such as Kerberos instead of relying on NTLM.

Patch My PC
  • The process starts with enhanced NTLM auditing to help organizations identify where NTLM is used. In the second half of 2026, Microsoft will introduce updates such as IAKerb, Local KDC, and changes to Windows components that currently use NTLM so they can use Negotiate authentication with Kerberos.
  • In the next version of Windows Server and Microsoft Windows clients, NTLM will be disabled by default in most cases, along with new policies to control or block NTLM usage.
  • These updates will help reduce dependency on NTLM across Windows and make authentication more secure and flexible.
TimelineUpdatesPurpose
TodayEnhanced auditingHelps to Identify Where NTLM used
Second half of 2026IAKerb, Local KDC, upgrade hard-coded NTLM to NegotiateReduces NTLM dependency.
Next version of Windows ServerNTLM disabled by default in most cases for Windows client and Windows ServerUnknown SPN, IP address, local accounts, NTLM block policies
Helps manage remaining NTLM scenarios.
Microsoft Plans to Disable NTLM by Default in Future Windows Versions -Table.1
Microsoft Plans to Disable NTLM by Default in Future Windows Versions -Fig.1 Creds to MS
Microsoft Plans to Disable NTLM by Default in Future Windows Versions -Fig.1 Creds to MS

How to Preparing to Disable NTLM

To prepare for disabling NTLM, organizations should enhance NTLM auditing to understand where it is being used in the environment. This helps administrators identify systems and services that still rely on NTLM. Organizations can also create an Allow List for specific servers and services that may need temporary exceptions to continue using NTLM. In addition, they can join the preview group to test features such as IAKerb and LocalKDC.

  • Finally, organizations should upgrade to Kerberos wherever possible to prepare for future updates in Microsoft Windows and Windows Server.
Microsoft Plans to Disable NTLM by Default in Future Windows Versions -Fig.2 Creds to MS
Microsoft Plans to Disable NTLM by Default in Future Windows Versions -Fig.2 Creds to MS

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community  and the Whatsapp channel to get the latest news on Microsoft Technologies. We are there on Reddit as well

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows,  Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update

Key Takeaways BitLocker Prompt Issue After June Patch KB5094126 Secure Boot UEFI 2023 Certificate Update! After deploying the June 2026 Windows update (KB5094126), some HP EliteDesk 800 G6 devices began prompting for the BitLocker recovery key after every reboot. Based on our investigation, the Secure Boot UEFI 2023 certificate update does not appear to be […]

AC Anoop C Nair 5 min read
Microsoft Defender for Endpoint

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Key Takeaways In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to […]

AC Anoop C Nair 5 min read