Why It Took Microsoft 32 Years to Disable NTLM
32 years. That is how long it took Microsoft to disable NTLM, the protocol that handles Windows login authentication. A broken system linked to $10 billion in damages and some of the worst cyberattacks ever recorded. Hackers have been exploiting it since 2001. Here is the story of why it took this long.
On January 30, 2026, Microsoft announced they will finally disable NTLM by default in future Windows releases.









