AI & Computingarticle2026-08-30

NTLM and Kerberos Explained with Diagrams — Why Authentication Falls Back to NTLM (archived 2026-08-30)

Open access0 citations

Abstract

An illustrated comparison of NTLM and Kerberos: challenge/response, TGTs and service tickets, the conditions under which Negotiate falls back to NTLM when an SPN cannot be resolved, why relay attacks and Pass-the-Hash work, and the removal of NTLMv1 — all backed by the official documentation. Archived version of https://comcomponent.com/en/blog/ntlm-kerberos-explained/, as published on 2026-08-30. The live article is maintained and may change after this date. First published 2026-07-26.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-30

Authors: Go Komura

Institutions: Fujikura (United States)