AD domain with multiple failed authentication attempts from invalid users via NTLM

Multiple failed NTLM authentication attempts from invalid users in an Active Directory domain may indicate a Password Spraying attack, exposing the environment to potential reconnaissance and privilege escalation.