Except that MS doesn't have the guts to remove insecure features, because the customers will get angry. I'm amazed they haven't changed the TPM requirement for Windows 11 yet, but there is still time
To be honest, the best bet that this will start really happening (NTLM removal), needed Server 2025. Local KDC. Although technically most would not need it but it helps on the fear that you mentioned.
Comments