← Back
KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication)
MC1050816 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-04-08 17:54:39
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Windows
Tags
Admin impact
Master tags
Security
Roadmap IDs

One-line summary

Windows updates from April 8, 2025 add protections for a Kerberos vulnerability; enforcement starts July 8, 2025, with full enforcement and registry key removal on October 14, 2025.

Similar updates

More like this
MC1111657 Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today
Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today Windows updates will enforce stricter certificate-based authentication from July 8, 2025, requiring CAs in the NTAuth store; full enforcement and policy bypass removal starts October 14, 2025. Additional information: For full technical details,.
MC1092195 Prepare for Kerberos CBA changes: Enforcement begins with July updates
...tes Windows updates will enforce stricter certificate-based authentication for domain controllers, requiring CAs in the NTAuth store starting July 8, 2025, with full enforcement October 14, 2025Starting with the April 8, 2025 Windows security updates, protections for CVE-2025-26647 are being rolled out and enforced in phases. Additional.
MC959496 Full Enforcement mode for certificate-based authentication on Windows DCs effective February 2025
Full Enforcement mode for certificate-based authentication on Windows DCs effective February 2025 Full Enforcement mode for certificate-based authentication on Windows domain controllers starts with February 2025 updates; non-compliant certificates will be denied authentication. The last phase of the changes to certificate-based authentication on.
MC1096052 Windows add support for the new certificate authority handling logic in Application Control for Business
Windows add support for the new certificate authority handling logic in Application Control for Business Application Control for Business updates CA trust logic to handle expiring Microsoft CAs, requiring Windows updates by May 13, 2025 for seamless trust extension. Microsoft is updating the logic used by Application Control for Business to.
MC1027793 30-day notice: Manage PAC Validation related to CVE-2024-26248 & CVE-2024-29056
30-day notice: Manage PAC Validation related to CVE-2024-26248 & CVE-2024-29056 Starting April 2025, Windows updates will enforce new Kerberos PAC Validation security behavior, removing Compatibility mode and requiring all domain controllers and clients to be updated. Last year, Windows updates released on or after April 9, 2024 added new.
MC1003098 60-day notice: Manage PAC Validation related to CVE-2024-26248 & CVE-2024-29056
60-day notice: Manage PAC Validation related to CVE-2024-26248 & CVE-2024-29056 Windows updates in April 2025 will enforce new Kerberos PAC Validation security behavior, removing Compatibility mode and requiring all domain controllers and clients to be updated. Last year, Windows updates released on or after April 9, 2024 added new behaviors that.

Details

Body (from Message Center)

The Windows security updates released on or after April 8, 2025, contain protections for a vulnerability with Kerberos authentication. To learn more about this vulnerability, please see CVE-2025-26647.
 
When will this happen:
April 8, 2025: Initial Deployment phase – Audit mode
  • The initial deployment phase starts with the updates released on April 8, 2025. These updates add new behavior that detects the elevation of privilege vulnerability described in CVE-2025-26647 but does not enforce it.
  • To enable the new behavior and be secure from the vulnerability, you must ensure all Windows domain controllers are updated and the AllowNtAuthPolicyBypass registry key setting is set to 2.

July 8 2025: Enforced by Default phase
  • Updates released on or after July 8, 2025, will enforce the NTAuth Store check by default. The AllowNtAuthPolicyBypass registry key setting will still allow customers to move back to Audit mode if needed. However, the ability to completely disable this security update will be removed.

October 14, 2025: Enforcement mode
  • Updates released on or after October 14, 2025, will discontinue Microsoft support for the AllowNtAuthPolicyBypass registry key. At this stage, all certificates must be issued by authorities that are a part of NTAuth store.
 
How this will affect your organization:
You are at risk when a certificate authority (CA) is part of the Windows root store but not the NTAuth store and a Subject Key Identifier (SKI) is present in a privileged account. To mitigate the risks, you must apply the protections described in CVE-2025-26647.
 
What you need to do to prepare:
  1. UPDATE all domain controllers with a Windows update released on or after April 8, 2025.
  2. MONITOR new events that will be visible on domain controllers to identify affected certificate authorities.
  3. ENABLE Enforcement mode once your environment is no longer using certificates issued by authorities that are not in the NTAuth store.
 
Additional information:

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Update all domain controllers with April 8, 2025 or later Windows updates",
      "Monitor domain controllers for new security events",
      "Ensure certificates are issued by NTAuth store authorities",
      "Prepare for enforcement and registry key removal"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Windows updates from April 8, 2025 add protections for a Kerberos vulnerability; enforcement starts July 8, 2025, with full enforcement and registry key removal on October 14, 2025.",
    "ai_topics": [
      "Windows",
      "Entra"
    ],
    "category": "stayInformed",
    "details_map": {},
    "id": "MC1050816",
    "importance": 5,
    "is_major_change": false,
    "last_modified": "2025-04-08T17:54:39Z",
    "ms_products": [
      "Windows"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Windows"
    ],
    "severity": "normal",
    "tags": [
      "Admin impact"
    ],
    "title": "KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication)"
  }
}