Active Directory Security - NTLM and Kerberos

Last modified by Sabrina V. on 2026/07/21 11:24

Within ACMP, NTLM is currently still used alongside Kerberos as an authentication method for LDAP queries, even though it is no longer recommended. Below is some info on where and why the various authentication methods are used:

Authentication with Kerberos

ACMP uses Kerberos as the authentication method by default when all components are members of the same domain. If a user logged in to the domain executes an LDAP Query, Kerberos enables secure authentication.

Authentication with NTLM

NTLM is used as an authentication method in ACMP in certain scenarios, such as when the ACMP Server is not part of the domain. In these scenarios, an LDAP Query is performed by the ACMP Server rather than by the ACMP Console. Because the server is not a member of the domain, Kerberos cannot be used, and NTLM is used instead. NTLM is also used when the SSL/TLS encryption method is not employed.

610_Einstellungen_Eigenschaften der Anmeldeinformationen_402.png

Credential Properties

Under what circumstances is it possible to disable NTLM?

A prerequisite for disabling NTLM is that both the server and all components that are supposed to or must use Kerberos for authentication are also members of the domain. External domains cannot be detected in this process, but subdomains are permitted. Only names (FQDNs/host names) may be used for communication between the relevant ACMP components.

Warning  Warning:  

The use of IP addresses is not recommended here, even though it would be technically possible. The reason for this is that Kerberos security measures could otherwise be circumvented. The Kerberos SPNs and DNS resolution must function correctly. Therefore, the Use static IPs checkbox must not be selected (see prior figure).

We also recommend using strong passwords (recommended length: about 14 characters) or, ideally, Managed Service Accounts to minimize overall password management.

When is each authentication method used?

Due to the technical architecture of ACMP, the authentication method is negotiated with the domain controller. If all technical requirements for Kerberos are met, Kerberos is always used first. NTLM is used as a fallback.

An external security specialist's assessment of the use of NTLM

There are scenarios in which the machines on which parts of ACMP are deployed cannot be members of a domain (e.g., due to incompatibilities or external domains). In these cases, it is not possible to use Kerberos, and NTLM must be used instead.
To ensure maximum security in such cases, an external security specialist was consulted regarding the use of NTLM in ACMP. The security specialist agrees that not all scenarios can be covered by Kerberos in the coming years. Microsoft is currently working on the development of a new authentication method (IAKerb) to cover all scenarios using both Kerberos and NTLM.
To ensure the highest possible security nonetheless, SSL/TLS should at least be activated. If necessary, the certificates for the requested domain must be imported for the host. Secure Authentication (ADS_SECURE_AUTHENTICATION) should also be used here, which ACMP does by default when using credentials. As with Kerberos, sufficiently long passwords should also be used.

Hinweis  Note:  

Regardless of LDAP authentication, the ACMP Server establishes SMB connections to remote systems using privileged credentials in various scenarios, such as during the ACMP Agent Installation. To reduce the risk of NTLM relay attacks on these connections, it is recommended that you enable client-side SMB signing on the ACMP Server.

 

© Aagon GmbH 2026
Besuchen Sie unsere aagon-Community