Your AD Password Policies Are Security Theater

Last week, Microsoft published a three-phase plan to kill the NTLM authentication protocol. My LinkedIn feed filled up with celebrations. And I get it, the protocol has been a source of pain for decades.

But almost nobody in those threads seems to understand a critical distinction, and it’s been bugging me enough to write this up with working proof-of-concept scripts so you can test it in your own lab.

This article has been indexed from DZone Security Zone

Read the original article: