This vulnerability in Windows only applies to domain authentication using NTLM/Netlogon. Authentication via Kerberos or FIPS is not exposed to this vulnerability and is not impacted by the patches being issued by Microsoft to address CVE-2022-38023.
We are in 9.9.1p3 now, and not ready to upgrade to 9.9.1p16 before 7/11, as the version that can support NTLM/Netlogon after AD patching.
I am not familiar with Domain Authentication, but my question is: Without upgrade ONTAP, is there anyway we can change the domain authentication from NTLM/Netlogon to Kerberos? If yes, what steps we would have to go through?