Trust is earned, not given

A different perspective

2024-10-08 · Projects

Windows domains, part 6: NTLM retirement, Server 2025, and the passwordless endgame

Part 6from the Windows domains series · 6 parts in all

In 2023 Microsoft did what this series has been building toward since part 3: it put NTLM on a deprecation path — first blocking NTLMv1 and turning off defaults in Windows 11 Insider builds, then shipping the policy switches that let you find and then forbid NTLM usage per-traffic-direction. Windows Server 2025 continues the arc. This closing part is the endgame: what changes, what breaks, and what the forest becomes.

Retiring a 30-year-old co-tenant, safely

The methodology matters more than the dates. Audit first — NTLM usage is visible as logon events where the authentication package is NTLM rather than Kerberos — then flip the audit policy, call every offending team, and only then enforce deny for incoming NTLM traffic. The two escape hatches that remove most legitimate NTLM: Kerberos for IP-addressed access (an SPN for the IP makes \\10.10.10.5 a Kerberos citizen) and completing SPN hygiene so fallback stops being triggered at all. What remains after that is small, and mostly legacy appliances that should be isolated or retired.

# 2024: find out who still leans on NTLM before you flip the policy
Get-WinEvent -FilterHashtable @{LogName='Security';Id=4624} -MaxEvents 500 |
  Where-Object { $_.Message -match 'NTLM' } |
  Select-Object TimeCreated, @{n='Who';e={$_.Properties[5].Value}}

# then enforce, in layers (these are policy values, not registry folklore):
#   Network security: Restrict NTLM: Audit Incoming NTLM traffic
#   Network security: Restrict NTLM: Incoming NTLM traffic = Deny all
#   Network security: Restrict NTLM: Outgoing NTLM traffic = Deny all

Server 2025 and the forest's new job

Windows Server 2025 reads less like a feature release and more like a consolidation: older crypto and protocols pruned, TLS 1.3 and channel-binding defaults tightened, SMB signing on by default, Kerberos PKINIT improvements for certificate logon. The forest's job description has inverted. In 2000 it was the universe; in 2025 it is a legacy identity plane with superb operational telemetry — the place where devices, file servers, and apps that cannot move still live, while the policy brain (Conditional Access, risk, lifecycle) runs in Entra ID. Cloud Kerberos trust closes the loop: a passwordless PRT can mint an on-prem-shaped TGT, so a FIDO2 user can still open \\fs01\share.

Beyond: what "domain" will mean next

Project the curves and the endgame is legible: devices managed by Intune instead of GPO; ZTNA tunnels (Entra Private Access) instead of network-perimeter VPNs; per-app, per-request identity instead of once-per-session logon; and the KDC itself surviving as a service rather than a room. The NT domain lasted ~20 years; the forest is two decades in and will outlive most readers' careers in some compatibility corner. But the direction is fixed and one-way: identity without shared secrets. The 1993 design proved you knew a secret; the 2030 design will prove your device is healthy and your credential is phishing-resistant — and the forest will be the well-documented bridge that got the enterprise there without breaking its file shares.

The whole series: 1 · the NT domain · 2 · AD and the forest · 3 · Kerberos vs NTLM · 4 · 2008R2-2019 features · 5 · hybrid identity · 6 · this article.