Which protocol does Windows use for securely authenticating domain users by default, replacing NTLM in modern Active Directory environments?