No you don't have to specifically enable it, it's still enabled (by default).
Completely disabling NTLM on a network would be a large project and not even Microsoft recommend that because the security gains are relatively small.
(See microsoft.com/pth for their comprehensive credential security guidance)
* Authenticating against a pre-NT 4.0 server * Accessing a domain resource via IP * Accessing a resource on a non-domain member * Accessing a resource on a computer that does not support Kerberos (Windows 3.11, Windows 95, etc.)
It's trivial to force this downgrade on most domains.
Windows will do Kerberos by default and avoid NTLM in lots of situations, but it's hard to keep it from being used at all if that's your goal.
Its so hard to get this right these days. I'm just recommending that people move all their clients to Azure AD join and put servers in resource forests.
NTLM has got to go and hardware/virtualization based security like device guard has to become the norm.
What is "disable NTLM", exactly: what does/doesn't happen?
Does it mean that NTLM hashes don't exist any more and therefore can't be sent anywhere?
Also, many, many places who do upgrade turn on legacy crap to interoperate and never turn them off. It's a lot of work to disable it, and the systems that still use it are usually old crap that isn't budgeted.