Beginning with Windows 2000, the initial authentication when you logon to a domain uses Kerberos but many applications continue to use older encryption schemes and the operating system supports this. The other available encryption methods are LM, NTLM and NTLMv2. The older encryption methods are relatively easy to crack with modern equipment so security best practices recommend only using the more recent NTLMv2 encryption where LAN Manager authentication is required.