
About this episode
It's time to retire NTLM - but how? Richard chats with Steve Syfuhs about the need and challenge of retiring an ubiquitous authentication protocol first used in the 1990s. While guidance to move away from NTLM has been available since 2010, it has only become feasible in the past couple of years, and Microsoft is now providing tooling to make the transition easier. Steve discusses enabling auditing of NTLM usage - recent improvements will allow you to view which services rely on NTLM. Sometimes, a configuration change can resolve the problem, and now there is Microsoft Negotiate to help as an intermediary in determining which protocol to use. Retiring NTLM won't happen overnight, but it will happen, and you can start preparing for it today. And if you need help or advice, email [email protected]!
Links
- NTLM Blocking and You
- Deprecating NTLM is Easy and Other Lies
- Microsoft Negotiate
- Remote Desktop Gateway Role
- Kerberos on Windows Server
- The Evolution of Windows Authentication
Recorded September 25, 2025
Get every episode summarized
Each time RunAs Radio publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from RunAs Radio

State of WSUS with Adam Marshall
RunAs Radio

Reimagining Intranets with Susan Hanley
RunAs Radio

Security Features of PowerShell 7 with Mike O'Neill
RunAs Radio

Automatic Attack Disruption with Liz Tesch
RunAs Radio