Replacing Acronis Cyber Files and leaving NTLM: Kerberos SSO for Android without the cloud
Two deadlines are converging on the same spot in the network this autumn: how company phones sign in, and how they reach the file shares. Acronis Cyber Files stops receiving security updates after 31 December 2026. And Microsoft is phasing out NTLM, with the first change to default behaviour announced for October 2026.
For Android and iOS this lands twice. The replacement mechanisms Microsoft is building exist only on Windows. If your phones and tablets reach the intranet, internal web apps and file shares via NTLM today, they need a Kerberos path. This post sets out what changes when, and how Hypergate, a Swiss vendor, closes both gaps: no cloud, no NTLM, and against the Active Directory you already run.
What Microsoft is changing
On 29 January 2026 Microsoft published a three-phase plan.
- Phase 1, available now: enhanced NTLM auditing in Windows Server 2025 and Windows 11 version 24H2 and later, so you can see where and why NTLM is still in use.
- Phase 2, second half of 2026: IAKerb and a local Key Distribution Center are meant to remove the most common reasons for NTLM fallback, such as no line of sight to a domain controller, or local accounts.
- Phase 3, with the next major Windows Server release: network NTLM is disabled by default and has to be switched back on explicitly through new policy controls.
A smaller step comes first. In October 2026 Microsoft plans to set the BlockNTLMv1SSO registry value to Enforce by default, so Windows stops generating NTLMv1-derived credentials for signed-in users. Microsoft describes both timelines as tentative (Microsoft Support).
NTLM is under attack, not just out of date
On 11 March 2025 Microsoft patched CVE-2025-24054, a flaw that makes Windows leak NTLM hashes to a remote server. Eight days later the first attacks were running. Check Point Research describes a campaign from 19 March 2025 whose main targets were government bodies and private institutions in Poland and Romania.
The attackers sent crafted .library-ms files, first inside ZIP archives and later on their own. Opening the folder that held the file, right-clicking it or dragging it was enough to trigger the flaw, and the hashes went to an SMB server run by the attackers. CISA added CVE-2025-24054 to its Known Exploited Vulnerabilities catalog on 17 April 2025.
A captured NTLM hash can be relayed to other services or cracked offline. None of that is new. It only stops where the network no longer needs NTLM, and that includes mobile devices.
What this means for Android and iOS
IAKerb and the local KDC are part of the Windows authentication stack. Android and iOS get none of it. Android Enterprise has no built-in Kerberos single sign-on, and Chrome on Android can only use Kerberos through a separate authenticator app. iOS has Apple's Kerberos SSO extension as a platform option; Android has no equivalent.
Once NTLM is blocked on the server side, mobile users notice first. Internal web apps return 401, SMB shares no longer mount, and on-premises SharePoint gets stuck in a sign-in loop (Hypergate, 25 June 2026).
Is there a European replacement for Acronis Cyber Files?
For mobile access to on-premises file servers, there is one from Switzerland: Hypergate Files, made by Papers AG in Zug. The app connects Android and iOS devices directly to Windows shares and NetApp over SMB2 and SMB3, authenticates with Kerberos, and keeps the permissions already set on the share. Files open in the apps already on the device, such as Word, Excel or a PDF viewer.
The main difference is architecture. Acronis Cyber Files needed its own servers: gateway, web server and database. Hypergate Files is client-only. Managed devices connect over the existing VPN straight to the SMB file server where the data already lives. No server is added, and company data is not stored locally on the device.
Day to day, the shares appear in the device's Files app, much like a mapped drive on a Windows PC. A Word document opens in Word, and changes are saved straight back to the share. DLP rules from the UEM still apply, for example blocking copies between the personal and work profiles.
The dates are set. Acronis Cyber Files and Acronis Files Connect reached end of life on 31 December 2025. Extended support with security updates ends on 31 December 2026.
Not everything Acronis Cyber Files did belongs in the same app. Hypergate Files does not cover sync or sharing files with external parties; those need their own route. The inventory will show which of these functions you actually use.
Kerberos SSO for Android against on-premises Active Directory
Hypergate Authenticator brings Kerberos to Android Enterprise from version 7.0 and to iOS. The app talks directly to the Key Distribution Center on your domain controllers. There is no extra server and no middleware, and sign-in stays inside your own network.
For users, that means signing in once and then opening the intranet and internal web apps without a password prompt, in regular Chrome or Microsoft Edge rather than only in a container browser. Hypergate lists SAP Fiori, ServiceNow, Jira and Confluence among the supported apps. ISEC7 MAIL, our secure email app for iPhone, iPad and Android, also supports Hypergate as a sign-in method.
For leaving NTLM behind, what matters is where the ticket comes from. Hypergate Authenticator requests it directly from the domain controller, either via PKINIT with a user certificate pushed to the device by the UEM, or with username and password. Either way, no NTLM hashes are created that could be captured and relayed, and credentials are not cached. On the domain controller, the mobile sign-in shows up in the event log as a Kerberos ticket request (event 4768), which gives security and compliance teams something they can verify.
The app also handles Active Directory environments with multiple forests, and users can change an expired password on the device without going to a Windows PC. Because Hypergate needs no external services, it also works in air-gapped networks with no internet access.
In-house Android apps: the Hypergate SDK
Not every internal application is a website. For in-house Android apps that sign in via NTLM today, there is the Hypergate SDK, published as com.hypergate:sdk on Maven Central. It fetches Kerberos tokens from the Authenticator on the device and adds them to the app's HTTP requests. WebViews authenticate without a single extra line of code. Native HTTP calls need one token call and one header per request.
Where to start
Before any switch comes the question of what still depends on NTLM and on Acronis.
- Inventory. Microsoft's enhanced NTLM auditing covers the Windows side. ISEC7 SPHERE, our platform for central monitoring of devices and systems, shows which devices and services still use the old sign-in method. Add the list of file servers that mobile users reach through Acronis today.
- Pilot. A test group receives Hypergate Authenticator and Hypergate Files through your existing UEM: Microsoft Intune, Ivanti, Omnissa Workspace ONE, BlackBerry UEM, SOTI or 42Gears. Hypergate offers a free proof of concept of around 30 days. You need the Kerberos port to the domain controllers open, plus port 445 for SMB.
- Rollout. Certificates, policies and app configuration come centrally from the UEM.
- Decommissioning. Only once every user has moved do the Acronis servers go offline.
If your team wants to get up to speed on Android Enterprise first, our Android training covers it.
Who does what
Hypergate makes the apps. ISEC7 is a Hypergate partner for Germany, the United Kingdom and the United States. We handle integration and rollout, and on request we run the setup for you.
Both apps were the subject of our webcast "The Sovereign Mobile Workplace" on 23 September 2026. Simon Kolb (ISEC7), together with Caglar Cölkusu and Lukas Schönbächler (Hypergate), presented them and showed them live. The recording is in German and available on request. For questions about your own environment, get in touch.
Sources
- Microsoft Windows IT Pro Blog, "Advancing Windows security: Disabling NTLM by default", 29 January 2026
- Microsoft Support, "Upcoming changes to NTLMv1 in Windows 11, version 24H2 and Windows Server 2025"
- Check Point Research, "CVE-2025-24054, NTLM Exploit in the Wild", 2025
- CISA, "CISA Adds Three Known Exploited Vulnerabilities to Catalog", 17 April 2025
- Acronis, "Acronis Cyber Files and Acronis Files Connect End of Life"
- Hypergate product pages, blog and webcast "The Sovereign Mobile Workplace", 23 September 2026