Introduction to NTLM and Kerberos Authentication: What is NTLM?
NTLM is a Microsoft Windows authentication protocol. It is a challenge-response authentication protocol that uses the MD4 hash function.
NTLM is designed to provide strong security, but it can be vulnerable to man-in-the-middle and replay attacks.
The NTLM protocol was developed by Microsoft in 1993 for use with the NT family of operating systems. The original name of the protocol was LanMan, but it was later changed to NTLM since this was a more descriptive name for what it does.
NTLM Authentication
NTLM is an authentication protocol in Windows Active Directory. NTLM uses an encrypted challenge-response authentication process to authenticate a user without sending its password over. We know that passwords are stored in Doman Controller in Active Directory.
First, the client sends an authentication request called NTLM Negotiate with user details. The Server replies with the NTLM Challenge (a 16-byte number). This number is encrypted with the hashed value of the client’s passwords. The server since it stores the passwords, it itself encrypts the challenge with the user password has and compares it with the response. If the values match, the user is authenticated.
NTLM as a Password-Based Protocol vs. Kerberos Authentication
NTLM is an authentication protocol that has been around since the 1990s. It uses a password-based system and it is vulnerable to hacks. It is not secure against brute force attacks.
Kerberos is an authentication protocol that was created in the 1980s and it uses a ticket-based system. Kerberos is more secure than NTLM as it does not use passwords.
Kerberos Authentication
In Kerberos Authentication for Active Directory, there are multiple servers involved and the security is enhanced compared to NTLM. There is a Key Distribution Centre that manages the password for all accounts which hosts a database and two servers namely the Authentication server and the Ticket granting server.
The Authentication server is used to authenticate the user and provide a ticket (Ticket-granting ticket or TGT) which is verified by Ticket Granting Server and then grants the access to the server. Let’s see what exactly happens in a scenario when an internal client wants to access a server (let’s say web) in a network.
- An authentication request is sent to the Authentication server which contains the username, system time, and service information which is encrypted with user password hash.
- The Authentication server accesses the database that contains the user password hash, decrypts the request and then grants a TGT (Ticket-granting Ticket) to the user which is encrypted with the Key Distribution Centre’s (KDC) password hash and the session key required to access the web server which is encrypted with user password hash.
- Now, the client will send session key and TGT to the Ticket Granting Server (TGS) to acquire the service ticket to access the server.
- The TGS will check the TGT and decrypt it with KDC Password hash to verify the authenticity of the ticket. If valid, it provides the service ticket to access the server. This service ticket, contains the user password hash encrypted with the web server’s password hash. Thus, this can only be decrypted by the server.
- Now, the user holds a session key and a service ticket. This is sent to the web server.
- This service ticket is decrypted by the web server with its password hash to find out the user password hash. Then, the user password hash is used to decrypt the session key and then the data communication starts.
Understanding the Benefits: NTLM vs Kerberos Authentication
NTLM authentication is a protocol that is used to authenticate the user to the server. It is an extension of the challenge-response authentication protocol and uses a challenge-response mechanism.
Kerberos authentication is a computer network authentication protocol which provides strong security, prevents man-in-the-middle attacks, and uses no passwords.
NTLM authentication can be used on networks that are disconnected from other networks while Kerberos cannot.
NTLM allows for more complicated password policies than Kerberos does because it has a larger character set and can use Unicode characters.
Conclusion: Which One Should You Choose?
NTLM is an old and outdated protocol that was created in the 1990s. It has a number of security flaws, so many companies are moving to Kerberos.
As a result, NTLM is not really worth considering anymore.



I ɑm regular reaɗeг, how aгe you everybody? This article posted at this weƅ page
is in fact good.
Hey Levin. Thanks for reading! Hope the post was informative.