**Credential Guard** — Windows feature that isolates LSASS in a virtual secure mode, preventing hash extraction - **Protected Users Security Group** — Members cannot authenticate via NTLM - **Restrict NTLM** — Group Policy settings to limit NTLM authentication - **Local Administrator Password Soluti