NTLM fallback preserves older trust assumptions

Older authentication protocols remain enabled for compatibility and carry weaknesses that newer ones fixed.

They are vulnerable to relay and to credential theft in ways Kerberos is not, and they persist because something old still needs them. Finding out what actually requires them is usually the blocker, and it is the prerequisite for turning them off.

More on Windows and Active Directory