Microsoft's plan to deprecate the NTLM authentication protocol doesn't eliminate the underlying security risk: the NT hash stored in Active Directory is also used by Kerberos, so it persists after migration. The SamrSetInformationUser RPC function allows setting a user's password hash directly in AD without submitting the
Sort: