NTLM

E196384

NTLM is a Microsoft authentication protocol used to validate users and secure access in Windows-based networks and services.

All labels observed (6)

Label Occurrences
NTLM canonical 14
NTLMv1 2
Windows Authentication 2

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf authentication protocol ⓘ
authentication protocol ⓘ
challenge–response authentication protocol ⓘ
authenticationModel client–server ⓘ
authenticationSteps negotiate, challenge, authenticate ⓘ
basedOn challenge–response mechanism ⓘ
canBeDisabledIn Windows security policy ⓘ
canBeRelayedOver HTTP ⓘ
SMB ⓘ
commonlyUsedOver untrusted networks (despite weaknesses) ⓘ
commonlyUsedWhen Kerberos is not available ⓘ
developedBy Microsoft ⓘ
discouragedBy modern security best practices ⓘ
documentedIn MS-NLMP specification ⓘ
doesNotNativelySupport multi-factor authentication ⓘ
doesNotSupport modern password hashing algorithms like bcrypt or scrypt ⓘ
hasVersion NTLMv1 ⓘ
NTLMv2 ⓘ
improvesOn NTLMv1 ⓘ
linked to: NTLM
introducedBy Microsoft Windows NT 4.0 SP4 ⓘ
linked to: Windows NT
predecessorOf Kerberos-based Windows integrated authentication ⓘ
recommendedReplacedBy Kerberos ⓘ
replaced LAN Manager (LM) authentication ⓘ
standardizedAs proprietary Microsoft protocol ⓘ
stillPresentIn many legacy Windows environments ⓘ
storesPasswordAs hash rather than plaintext ⓘ
supports mutual authentication (in some variants) ⓘ
session security (signing and sealing) ⓘ
usedBy HTTP authentication (via NTLM HTTP auth) ⓘ
MSRPC ⓘ
linked to: Microsoft RPC

Remote Desktop Protocol (RDP) ⓘ
SMB protocol ⓘ
linked to: SMB

SQL Server (integrated authentication) ⓘ
linked to: SQL Server
usedFor access control ⓘ
network authentication ⓘ
single sign-on in Windows networks ⓘ
user authentication ⓘ
usedIn Active Directory environments (as fallback) ⓘ
Windows domain environments ⓘ
Windows operating systems ⓘ
linked to: Windows

Windows workgroup environments ⓘ
uses HMAC-MD5 (in NTLMv2) ⓘ
MD4-based hashing (for NT hash) ⓘ
Windows credentials database ⓘ
domain controller for domain authentication ⓘ
vulnerableTo brute-force attacks on weak passwords ⓘ
pass-the-hash attacks ⓘ
relay attacks ⓘ
weakerThan Kerberos ⓘ

How these facts were elicited

Referenced by (21)

Full triples — surface form annotated when it differs from this entity's canonical label.

SQL Server Integration Services → supportsSecurityFeature → Windows Authentication ⓘ
linked to: NTLM
Thunderbird → supportsAuthentication → NTLM ⓘ
subject linked to: Thunderbird email client
NTLMv2 → improvesOn → NTLMv1 ⓘ
subject linked to: NTLM
linked to: NTLM
Enterprise Manager → supportsAuthentication → Windows Authentication ⓘ
linked to: NTLM
MD4 → usedIn → NTLM (legacy) ⓘ
linked to: NTLM
MS-NLMP specification → defines → NTLM authentication protocol ⓘ
linked to: NTLM
MS-NLMP specification → covers → NTLMv1 ⓘ
linked to: NTLM
MS-NLMP specification → covers → NTLMv2 ⓘ
linked to: NTLM