Two deadlines are converging on the same spot in the network this autumn: how company phones sign in, and how they reach the file shares. Acronis Cyber Files stops receiving security updates after 31 December 2026. And Microsoft is phasing out NTLM, with the first change to default behaviour announced for October 2026.
For Android and iOS this lands twice. The replacement mechanisms Microsoft is building exist only on Windows. If your phones and tablets reach the intranet, internal web apps and file shares via NTLM today, they need a Kerberos path. This post sets out what changes when, and how Hypergate, a Swiss vendor, closes both gaps: no cloud, no NTLM, and against the Active Directory you already run.
On 29 January 2026 Microsoft published a three-phase plan.
A smaller step comes first. In October 2026 Microsoft plans to set the BlockNTLMv1SSO registry value to Enforce by default, so Windows stops generating NTLMv1-derived credentials for signed-in users. Microsoft describes both timelines as tentative (Microsoft Support).
On 11 March 2025 Microsoft patched CVE-2025-24054, a flaw that makes Windows leak NTLM hashes to a remote server. Eight days later the first attacks were running. Check Point Research describes a campaign from 19 March 2025 whose main targets were government bodies and private institutions in Poland and Romania.
The attackers sent crafted .library-ms files, first inside ZIP archives and later on their own. Opening the folder that held the file, right-clicking it or dragging it was enough to trigger the flaw, and the hashes went to an SMB server run by the attackers. CISA added CVE-2025-24054 to its Known Exploited Vulnerabilities catalog on 17 April 2025.
A captured NTLM hash can be relayed to other services or cracked offline. None of that is new. It only stops where the network no longer needs NTLM, and that includes mobile devices.
IAKerb and the local KDC are part of the Windows authentication stack. Android and iOS get none of it. Android Enterprise has no built-in Kerberos single sign-on, and Chrome on Android can only use Kerberos through a separate authenticator app. iOS has Apple's Kerberos SSO extension as a platform option; Android has no equivalent.
Once NTLM is blocked on the server side, mobile users notice first. Internal web apps return 401, SMB shares no longer mount, and on-premises SharePoint gets stuck in a sign-in loop (Hypergate, 25 June 2026).
For mobile access to on-premises file servers, there is one from Switzerland: Hypergate Files, made by Papers AG in Zug. The app connects Android and iOS devices directly to Windows shares and NetApp over SMB2 and SMB3, authenticates with Kerberos, and keeps the permissions already set on the share. Files open in the apps already on the device, such as Word, Excel or a PDF viewer.
The main difference is architecture. Acronis Cyber Files needed its own servers: gateway, web server and database. Hypergate Files is client-only. Managed devices connect over the existing VPN straight to the SMB file server where the data already lives. No server is added, and company data is not stored locally on the device.
Day to day, the shares appear in the device's Files app, much like a mapped drive on a Windows PC. A Word document opens in Word, and changes are saved straight back to the share. DLP rules from the UEM still apply, for example blocking copies between the personal and work profiles.
The dates are set. Acronis Cyber Files and Acronis Files Connect reached end of life on 31 December 2025. Extended support with security updates ends on 31 December 2026.
Not everything Acronis Cyber Files did belongs in the same app. Hypergate Files does not cover sync or sharing files with external parties; those need their own route. The inventory will show which of these functions you actually use.
Hypergate Authenticator brings Kerberos to Android Enterprise from version 7.0 and to iOS. The app talks directly to the Key Distribution Center on your domain controllers. There is no extra server and no middleware, and sign-in stays inside your own network.
For users, that means signing in once and then opening the intranet and internal web apps without a password prompt, in regular Chrome or Microsoft Edge rather than only in a container browser. Hypergate lists SAP Fiori, ServiceNow, Jira and Confluence among the supported apps. ISEC7 MAIL, our secure email app for iPhone, iPad and Android, also supports Hypergate as a sign-in method.
For leaving NTLM behind, what matters is where the ticket comes from. Hypergate Authenticator requests it directly from the domain controller, either via PKINIT with a user certificate pushed to the device by the UEM, or with username and password. Either way, no NTLM hashes are created that could be captured and relayed, and credentials are not cached. On the domain controller, the mobile sign-in shows up in the event log as a Kerberos ticket request (event 4768), which gives security and compliance teams something they can verify.
The app also handles Active Directory environments with multiple forests, and users can change an expired password on the device without going to a Windows PC. Because Hypergate needs no external services, it also works in air-gapped networks with no internet access.
Not every internal application is a website. For in-house Android apps that sign in via NTLM today, there is the Hypergate SDK, published as com.hypergate:sdk on Maven Central. It fetches Kerberos tokens from the Authenticator on the device and adds them to the app's HTTP requests. WebViews authenticate without a single extra line of code. Native HTTP calls need one token call and one header per request.
Before any switch comes the question of what still depends on NTLM and on Acronis.
If your team wants to get up to speed on Android Enterprise first, our Android training covers it.
Hypergate makes the apps. ISEC7 is a Hypergate partner for Germany, the United Kingdom and the United States. We handle integration and rollout, and on request we run the setup for you.
Both apps were the subject of our webcast "The Sovereign Mobile Workplace" on 23 September 2026. Simon Kolb (ISEC7), together with Caglar Cölkusu and Lukas Schönbächler (Hypergate), presented them and showed them live. The recording is in German and available on request. For questions about your own environment, get in touch.