Hi,
Based on Microsoft documentation , you can establish a trust between active directory on windows 2012 R2 and Windows NT 4.0:
trust-between-windows-ad-domain-not-work-correctly
I recommend you to remove WIndows NT soon as possible, because when you keep Windows NT you will be enable to disable vulnerable protocol.
Please don't forget to mark helpful reply as answer