Initial deployment phase for Kerberos RC4 hardening begins with the January 2026 Windows security update
Windows updates released on and after January 13, 2026, introduce the first phase of protections addressing a Kerberos information disclosure vulnerability (CVE‑2026‑20833). These updates introduce new auditing and optional registry controls that devices can use to begin reducing reliance on RC4 encryption. They also help prepare domain controllers for a future shift to AES‑SHA1 as the default Kerberos encryption method for accounts without explicit encryption settings. The initial deployment phase focuses on identifying misconfigurations or dependencies before the second deployment phase begins in April 2026. When this will happen: The initial deployment phase starts January 13, 2026, and introduces new Kerberos audit events that help identify any remaining RC4 dependencies across your environment. This phase also adds the temporary RC4DefaultDisablementPhase registry value, which organizations can use to optionally enable the upcoming behavior changes early; however, this key will no longer be read after Audit mode is removed in July 2026. Together, these updates provide early diagnostics to help assess readiness before the second deployment phase in April 2026, when the default domain controller behavior for Kerberos encryption will change to use AES‑SHA1 only for accounts without explicit encryption settings. Starting in April 2026, Enforcement mode will be enabled on all Windows domain controllers by default, and in July 2026 Audit mode will be removed, leaving Enforcement mode as the only option. How this will affect your organization: Domain controllers will begin logging new Kerberos audit events, KDCSVC (ID 201–209), that highlight where devices or service accounts still rely on RC4 encryption. Certain RC4‑dependent configurations will appear in the new Kerberos audit events, highlighting scenarios that will become incompatible once enforcement begins. These events provide early visibility into configurations that may fail as Enforcement mode is enabled by default starting in April 2026 and Audit mode is removed in July 2026. As the deployment phases progress, beginning with the April 2026 Windows security update, Kerberos operations will shift to using AES‑SHA1 by default for accounts without explicit encryption settings. Environments that do not address RC4 dependencies may experience authentication issues as Enforcement mode is enabled by default starting in April 2026 […]
The post Initial deployment phase for Kerberos RC4 hardening begins with the January 2026 Windows security update appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Initial deployment phase for Kerberos RC4 hardening begins with the January 2026 Windows security update
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
External messaging limits for onmicrosoft.com-only organizations in Microsoft Teams
Microsoft Teams will impose outbound external messaging limits starting mid-September 2026 for organizations using only the default onmicrosof...
Microsoft Teams: Enable agents for existing applications in your organization
For third-party applications already being used in your organization, admins can now discover and enable the corresponding Teams agents from w...
Microsoft Viva: Campaigns Hub in Engage and Engage in Teams mobile
The Campaigns Hub in Viva Engage provides a centralized mobile destination where employees can discover and participate in organizational camp...
Planner: Conditional Coloring
Conditional Coloring highlight tasks based on selected criteria, making priorities, status, and important task details easier to spot. Product...
Outlook: Offline settings “Days of email to save” admin policy
Tenant admins will be able to define the default value for “Days of email to save” in Offline settings and designate whether end u...
Microsoft Copilot Studio: Agent Sharing amongst makers
Enables sharing of agents with other makers in the new GHCP harness. Makers can grant other makers Agent Viewer (view analytics/evaluations on...
OneDrive Photos on Windows: admin controls and policy support
OneDrive Photos, integrated into the OneDrive sync app for Windows 10/11, is currently available only for personal Microsoft accounts, with wo...
Admin app retiring in Teams, Outlook and Microsoft365.com
The Admin app for very small businesses in Teams, Outlook, and Microsoft365.com will retire by October 2026, with rollout starting August 2026...
Calls popout into a new window on the browser to support multi-tasking and collaboration during a meeting
Microsoft Teams for Web will introduce a Picture-in-Picture Call Monitor in October 2026, allowing users to manage meeting controls in a separ...
Microsoft Windows Autopatch: September 2026 Windows security update requires a restart for hotpatch-enabled devices
The September 2026 Windows security update requires a restart for hotpatch-enabled devices because it is a standard update. Devices will remai...