Microsoft confirms spike in NTLM authentication traffic after Windows Server patch
- Reference: 1714650310
- News link: https://www.theregister.co.uk/2024/05/02/microsoft_ntlm_windows_server/
- Source link:
The issue is caused by installing the update ( [1]KB5036909 ) on domain controllers. NTLM traffic might then suddenly spike.
The problem comes hot on the heels of [2]VPN connection failures in the same update.
[3]
According to Microsoft's [4]release health dashboard : "This issue is likely to affect organizations that have a very small percentage of primary domain controllers in their environment and high NTLM traffic."
[5]
[6]
Microsoft said it is "working on a resolution and will provide an update in an upcoming release." A user could uninstall the patch, but doing so would also remove the security fixes included in the update.
[7]Microsoft's FOMO after seeing Google AI drove investment in OpenAI
[8]Microsoft confesses April Windows update breaks some VPN connections
[9]Microsoft boss charms Indonesia with $1.7B AI, cloud injection
[10]More big city newspapers drag Microsoft, OpenAI hard in copyright lawsuit
NTLM – New Technology LAN Manager – is a very old suite of Microsoft security protocols designed to authenticate users. Microsoft would like people to [11]stop using the technology , but enterprises cling to it. There is, after all, always that one weird app written decades ago that was hard-coded to use it.
In a [12]blog post on the matter, Microsoft said: "Kerberos has been the default Windows authentication protocol since 2000, but there are still scenarios where it can't be used and where Windows falls back to NTLM."
This is because NTLM doesn't need a local network connection to a DC and will work when the target server is unknown. Both scenarios can be problematic for Kerberos despite the authentication protocol being a good deal more secure. Hence prying enterprises away from NTLM has proven a challenge.
[13]
Microsoft said: "Our end goal is eliminating the need to use NTLM at all to help improve the security bar of authentication for all Windows users."
Ramping up traffic on networks of customers who have yet to heed Microsoft's advice is certainly one way of achieving that goal, even though we're pretty sure this wasn't the company's intention. ®
Get our [14]Tech Resources
[1] https://support.microsoft.com/en-gb/topic/april-9-2024-kb5036909-os-build-20348-2402-36062ce9-f426-40c6-9fb9-ee5ab428da8c
[2] https://www.theregister.com/2024/05/01/microsoft_windows_vpn_problems/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjO4n7en6HtsE7YV8LYFjAAAAMo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://learn.microsoft.com/en-gb/windows/release-health/status-windows-server-2022#3292msgdesc
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjO4n7en6HtsE7YV8LYFjAAAAMo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjO4n7en6HtsE7YV8LYFjAAAAMo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/05/01/openai_microsoft_email/
[8] https://www.theregister.com/2024/05/01/microsoft_windows_vpn_problems/
[9] https://www.theregister.com/2024/04/30/microsoft_indonesia_investment/
[10] https://www.theregister.com/2024/04/30/newspapers_microsoft_openai/
[11] https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-evolution-of-windows-authentication/ba-p/3926848
[12] https://techcommunity.microsoft.com/t5/windows-it-pro-blog/the-evolution-of-windows-authentication/ba-p/3926848
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjO4n7en6HtsE7YV8LYFjAAAAMo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
Why can't they make it that if you want NTLM you have to add it back yourself.
Declare it unfit and clearly lay out the security problems with it and let people continue to use it but you get no support and no basis to complain as you had been duly warned about the dangers of its continued use.
This pussyfooting that "we don't recommend it, and its insecure but will be the provided and made the failover" just seems insane when they themselves say it should not be used. Well you write the stuff so stop inducing.
People are lazy and will use a tool if 8ts already there and seems to be working, so lazy they won't check if it *is* working. They will only move when made to. So make them.
Yeah yeah, "do you know how many systems... Etc." Sure but how many more will it be if they leave it and it keeps getting used and ever more insecure.
And knowing its the failover could lead to peo0le targeting the kerberos end not to exploit it but to make it fail and thus get to using the known insecure backup.
Microsoft is retiring
So many Microsoft aspects that we have been using for years now are no longer working or just working badly, basically the company is probably heading for closure at some time in the future.
I'm having to delete Microsoft OneDrive everywhere today because it's no longer reliably functional and all the current Microsoft operating systems don't work as well as their original versions. So many old companies are only busy generating income, not excited users like they did initially..
"New Technology LAN Manager – is a very old suite"
Nothing ages a product so much as calling it "New".
"It was a new day yesterday
But it's an old day now"
Yes, NTLMv1 is old and should be disabled, but...
...NTLMv2 is still widely used. For a large corporation, I assume it would take years to eliminate all software and user activity that uses NTLM in some way.