Reply to Message
Starting with Windows 7 and Server 2008-R2, it is possible to disable NTLM entirely in favor of Kerberos. Kerberos isn't perfect, and Kerberos doesn't stop pass-the-hash attacks either, but Microsoft is aware of the need to eventually get away from NTLM (sooner rather than later).
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox




