Loading...

Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today

Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today

Starting with the April 8, 2025, Windows security updates, protections for CVE-2025-26647 are being rolled out and enforced in phases. These updates change how certificate-based authentication (CBA) is handled when the issuing certificate authority (CA) is not in the NTAuth store but a Subject Key Identifier (SKI) mapping exists in the altSecID attribute. The second phase, Enforced by Default phase, begins today, July 8, 2025. When will this happen: July 8, 2025: Enforced by Default phase Updates released on or after July 8, 2025, will enforce the NTAuth store check by default. The AllowNtAuthPolicyBypass registry key setting will still allow customers to move back to Audit mode if needed. However, the ability to completely disable this security update will be removed. October 14, 2025: Enforcement mode Updates released on or after October 14, 2025, will discontinue Microsoft support for the AllowNtAuthPolicyBypass registry key. At this stage, all certificates must be issued by authorities that are a part of NTAuth store. How this will affect your organization: If your environment uses CBA and relies on certificates from CAs not in the NTAuth store, authentication may fail once Enforcement mode is enabled. This change affects domain controllers and requires updates to ensure secure authentication behavior. New audit events will help identify affected certificates and CAs.   What you need to do to prepare:   Additional information: For full technical details, including registry settings and audit event IDs, see KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) UPDATE all domain controllers with a Windows update released on or after April 8, 2025. MONITOR new events (e.g., Event ID 45 and 21) that will be visible on domain controllers to identify affected certificate authorities. ENABLE Enforcement mode after your environment is now only using logon certificates issued by authorities that are in the NTAuth store. REVIEW AND UPDATE altSecID mappings if needed to ensure compatibility. To learn more about these protections, please see Guidance for applying protections related to CVE-2025-26647. Message ID: MC1111657

The post Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Teams: Enhanced real-time alerting rule management in the Teams admin center

Microsoft Teams will enhance Real-Time Alerting rule management in the Teams admin center by enabling rule duplication, bulk user uploads, and...

1 day ago

Copilot Studio – Use MCP-compliant tools in agent workflows

We are announcing the ability to use MCP (model context protocol) – compliant tools in agent workflows in Microsoft Copilot Studio. This...

1 day ago

Microsoft Teams: Personal message reminders for chat and channels

Microsoft Teams will introduce personal message reminders for chat and channel messages in October 2026. Users can set, manage, and receive no...

1 day ago

M365 Copilot: Tell Copilot what you need directly from the Copilot button in Word, Excel, and PowerPoint

Microsoft 365 Copilot adds a new prompt input directly on the Copilot button in Word, Excel, and PowerPoint for faster, contextual content cre...

1 day ago

Microsoft Outlook for iPad: Minimize email drafts and return to them later

Outlook for iPad will allow users to compose emails in a separate window and minimize drafts to return later, enhancing multitasking. This fea...

1 day ago

Microsoft Purview eDiscovery: Select user-owned SharePoint Embedded containers as a data source

Microsoft Purview eDiscovery will support selecting user-owned SharePoint Embedded containers as data sources for cases, searches, and holds s...

1 day ago

Microsoft Purview: Removing pay-as-you-go requirements for Edge for Business DLP unmanaged app protections

Starting mid-October 2026, Microsoft Purview will remove the pay-as-you-go billing requirement for inline collection and DLP policies protecti...

1 day ago

Data Privacy: Microsoft Online Services Subprocessor Disclosure

This notice provides an update to the Microsoft Online Services Subprocessors List. Microsoft may engage non-Microsoft organizations to help p...

1 day ago

Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details

User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a securit...

1 day ago

30-Day Reminder: Windows Server 2022 will reach end of mainstream support on October 13, 2026

On October 13, 2026, Windows Server 2022 will reach end of mainstream support. The October 2026 security update will be the last mainstream su...

1 day ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.