NTLM fallback preserves older trust assumptions
Older authentication protocols remain enabled for compatibility and carry weaknesses that newer ones fixed.
They are vulnerable to relay and to credential theft in ways Kerberos is not, and they persist because something old still needs them. Finding out what actually requires them is usually the blocker, and it is the prerequisite for turning them off.
More on Windows and Active Directory
- Domain Admin is a forest-scale keyOne root under the whole forest
- Kerberos tickets are credentialsWhoever holds it, gets in
- Golden Ticket attacks target the ticket authorityThey took the press, not a ticket
- Group Policy is a fleet control planeOne dial, every desk
- LAPS reduces shared local-admin secretsOne secret, or one each
- Service accounts can become invisible administratorsThe pass with no face
