Several legacy line-of-business apps still require NTLM-only authentication and thereby block MFA enforcement for those pathways. What should the security program prioritize?
Select an answer to reveal the explanation.
Short Explanation
NTLM-only dinosaurs hold the MFA rollout hostage. Do not pretend NTLM is a security key—put compensating gates around them and schedule the move to modern auth that can actually do MFA.
Full Explanation
Legacy protocols such as NTLM lack strong MFA integration and broaden relay and credential-theft risk. Programs should inventory NTLM dependencies, apply compensating network and access controls, and retire or modernize apps toward protocols that support phishing-resistant MFA. Equating NTLM to FIDO2, Internet-exposing NTLM, or disabling MFA organization-wide are unsafe shortcuts.