NTLM auth traffic spikes after Windows Server patch
Briefly

The issue is caused by installing the update ( KB5036909) on domain controllers. NTLM traffic might then suddenly spike.
NTLM is an old suite of Microsoft security protocols used when Kerberos can't be deployed, but Microsoft aims to eliminate its use for improved security.
Read at Theregister
[
|
]