Access Denied: Knowing When Win2K Uses NTLM Rather Than Kerberos Authentication

I've read that Kerberos replaces the much weaker Windows NT LAN Manager (NTLM) authentication in Windows 2000 and later. Are there any circumstances under which Win2K still uses NTLM?

Yes, Win2K still uses NTLM in certain situations. You should know the circumstances under which this occurs because NTLM is much more vulnerable to eavesdropping and subsequent cracking. For Win2K to use Kerberos when a user logs on, all computers involved—workstations, domain controllers (DCs), and servers—must be Win2K or later and members of the same domain or at least the same forest. In addition, the user account that's logging on must be an Active Directory (AD) user account, not an account in a computer's local SAM or an account from an NT domain.

In the following situations, NTLM rather than Kerberos authenticates logons. When a user with an AD domain account logs on at an NT or Windows 9x workstation, NTLM will authenticate the logon because pre-Win2K versions of Windows don't support Kerberos. For the same reason, even when a user logs on with an AD domain account to a Win2K workstation but maps a drive to an NT server, NTLM will authenticate the logon. Also, when a user maps a drive to a Win2K server but uses a local account in that server's SAM, Win2K uses NTLM—even if the workstation and server are part of an AD domain.

Discuss this Article 1

Jason Winder (not verified)
on Apr 21, 2003
NTLM is also used prior to W2K3 for interforest trusts. Note that W2K3 introduces "forest trusts", which are available only in .NET forest mode, and which use Kerberos for the secure trust channel. Also note, by the way, that "shortcut" trusts that are created WITHIN a forest always use Kerberos.

Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• The Microsoft
Technology Roadmap
• Office 365 Implementation
• Hyper-V Optimizing
• Windows 8 Deployment
and much more!

Come See Paul Thurrott & Rod Trent in Person!

Early Registration Now Open

Upcoming Training

Mastering SharePoint 2013: Succeeding, Not Just Surviving

Building on the success of the “Mastering SharePoint 2010” seminars, the presenters have updated the content to cover the latest and greatest SharePoint product: SharePoint 2013. While SharePoint 2013 is relatively new on the marketplace, the presenters have been working with SharePoint 2013 for well over a year, and have implemented it with a number of clients in production environments.

Register Now

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.