When it has been determined that the NTLM authentication protocol should not be used within a domain because you are required to use a more secure protocol, such as Kerberos protocol, there might be some client applications that still use NTLM. If so, and you set Network Security: Restrict NTLM: NTLM authentication in this domain to any of the Deny options, those applications will fail because the