Loading...

Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today

Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today

Starting with the April 8, 2025, Windows security updates, protections for CVE-2025-26647 are being rolled out and enforced in phases. These updates change how certificate-based authentication (CBA) is handled when the issuing certificate authority (CA) is not in the NTAuth store but a Subject Key Identifier (SKI) mapping exists in the altSecID attribute. The second phase, Enforced by Default phase, begins today, July 8, 2025. When will this happen: July 8, 2025: Enforced by Default phase Updates released on or after July 8, 2025, will enforce the NTAuth store check by default. The AllowNtAuthPolicyBypass registry key setting will still allow customers to move back to Audit mode if needed. However, the ability to completely disable this security update will be removed. October 14, 2025: Enforcement mode Updates released on or after October 14, 2025, will discontinue Microsoft support for the AllowNtAuthPolicyBypass registry key. At this stage, all certificates must be issued by authorities that are a part of NTAuth store. How this will affect your organization: If your environment uses CBA and relies on certificates from CAs not in the NTAuth store, authentication may fail once Enforcement mode is enabled. This change affects domain controllers and requires updates to ensure secure authentication behavior. New audit events will help identify affected certificates and CAs.   What you need to do to prepare:   Additional information: For full technical details, including registry settings and audit event IDs, see KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) UPDATE all domain controllers with a Windows update released on or after April 8, 2025. MONITOR new events (e.g., Event ID 45 and 21) that will be visible on domain controllers to identify affected certificate authorities. ENABLE Enforcement mode after your environment is now only using logon certificates issued by authorities that are in the NTAuth store. REVIEW AND UPDATE altSecID mappings if needed to ensure compatibility. To learn more about these protections, please see Guidance for applying protections related to CVE-2025-26647. Message ID: MC1111657

The post Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Customized PowerBI reports behavior after major report updates

Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...

5 hours ago

Microsoft SharePoint: Changes to the FAQ web part authoring experience

The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...

5 hours ago

Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions

Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...

5 hours ago

Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout

Microsoft Defender for Office 365 will enhance the Teams message entity flyout by late September 2026, enabling security admins to submit mess...

5 hours ago

Microsoft 365 Copilot: Updates to the Researcher experience

Microsoft 365 Copilot is updating Researcher to use shared Copilot components, retiring specific controls and tabs by December 30, 2026. Core ...

5 hours ago

Dynamics 365 Field Service – Automate optimizations with Scheduling Operations Agent (Preview)

We are announcing the ability to automatically schedule and run recurring optimizations through the Scheduling Operations Agent in Dynamics 36...

7 hours ago

Dynamics 365 Contact Center – Enable AI-assisted time-off and swap requests

We are announcing the ability to enable AI-assisted time-off and swap requests in Dynamics 365 Contact Center. This feature will reach general...

7 hours ago

Dynamics 365 Project Operations – Perform bulk operations for bookings on schedule board

We are announcing the ability to move or reassign multiple bookings at once, directly from the schedule board in Dynamics 365 Project Operatio...

7 hours ago

Browser Use Admin Control for Copilot Cowork

Admins can now control browser use in Copilot Cowork via Microsoft 365 admin center, enabling access for specific users or groups. Rolling out...

7 hours ago

Microsoft Copilot (Microsoft 365): Power BI reports as references in Copilot Notebooks

Copilot Notebooks now support adding Power BI reports as references, enhancing summaries with real business data. Public preview starts late S...

7 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.