Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-07-08 17:02:41
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
—
Action by (AI)
—
Services
Windows
Tags
Admin impact
Master tags
Security
Roadmap IDs
One-line summary
Windows updates will enforce stricter certificate-based authentication from July 8, 2025, requiring CAs in the NTAuth store; full enforcement and policy bypass removal starts October 14, 2025.
Similar updates
More like thisMC1092195 Prepare for Kerberos CBA changes: Enforcement begins with July updates
Prepare for Kerberos CBA changes: Enforcement begins with July updates Windows updates will enforce stricter certificate-based authentication for domain controllers, requiring CAs in the NTAuth store starting July 8, 2025, with full enforcement October 14, 2025. Starting with the April 8, 2025 Windows security updates, protecti... Additional.
MC1050816 KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication)
KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) Windows updates from April 8, 2025 add protections for a Kerberos vulnerability; enforcement starts July 8, 2025, with full enforcement and registry key removal on October 14, 2025. The Windows security updates released on or after April 8, 2025, contain protections for a.
MC1104112 (Updated) Act now: Secure Boot certificates expire in June 2026
(Updated) Act now: Secure Boot certificates expire in June 2026 Microsoft will roll out updated Secure Boot certificates for Windows systems; current certificates start expiring June 2026, re... Updated July 8, 2025: survey link changed In the coming months, Microsoft will be rolling out updated Secure Boot certificates needed to ensure a secure.
MC1143929 Certificate-based authentication changes on Windows domain controllers - coming September 2025
Certificate-based authentication changes on Windows domain controllers - coming September 2025 Starting with September 2025 Windows updates, strict certificate mapping will be enforced on AD CS and domain controllers, blocking authentication if requirements aren't met. Since 2023, Microsoft has been sharing reminders of changes coming to.
MC959496 Full Enforcement mode for certificate-based authentication on Windows DCs effective February 2025
Full Enforcement mode for certificate-based authentication on Windows DCs effective February 2025 Full Enforcement mode for certificate-based authentication on Windows domain controllers starts with February 2025 updates; non-compliant certificates will be denied authentication. The last phase of the changes to certificate-based authentication on.
MC1096052 Windows add support for the new certificate authority handling logic in Application Control for Business
Windows add support for the new certificate authority handling logic in Application Control for Business Application Control for Business updates CA trust logic to handle expiring Microsoft CAs, requiring Windows updates by May 13, 2025 for seamless trust extension. Microsoft is updating the logic used by Application Control for Business to.
Details
Body (from Message Center)
Starting with the April 8, 2025, Windows security updates, protections for CVE-2025-26647 are being rolled out and enforced in phases. These updates change how certificate-based authentication (CBA) is handled when the issuing certificate authority (CA) is not in the NTAuth store but a Subject Key Identifier (SKI) mapping exists in the altSecID attribute.
The second phase, Enforced by Default phase, begins today, July 8, 2025.
When will this happen:
July 8, 2025: Enforced by Default phase
- Updates released on or after July 8, 2025, will enforce the NTAuth store check by default. The AllowNtAuthPolicyBypass registry key setting will still allow customers to move back to Audit mode if needed. However, the ability to completely disable this security update will be removed.
October 14, 2025: Enforcement mode
- Updates released on or after October 14, 2025, will discontinue Microsoft support for the AllowNtAuthPolicyBypass registry key. At this stage, all certificates must be issued by authorities that are a part of NTAuth store.
How this will affect your organization:
If your environment uses CBA and relies on certificates from CAs not in the NTAuth store, authentication may fail once Enforcement mode is enabled. This change affects domain controllers and requires updates to ensure secure authentication behavior. New audit events will help identify affected certificates and CAs.
What you need to do to prepare:
- UPDATE all domain controllers with a Windows update released on or after April 8, 2025.
- MONITOR new events (e.g., Event ID 45 and 21) that will be visible on domain controllers to identify affected certificate authorities.
- ENABLE Enforcement mode after your environment is now only using logon certificates issued by authorities that are in the NTAuth store.
- REVIEW AND UPDATE altSecID mappings if needed to ensure compatibility.
Additional information:
- For full technical details, including registry settings and audit event IDs, see KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication)
To learn more about these protections, please see Guidance for applying protections related to CVE-2025-26647.
Raw JSON (for debugging)
Expand/collapse the full payload below.
Show/hide raw
{
"snapshot_item": {
"action_required_by": null,
"ai_action_required_by": null,
"ai_actions": [
"Update all domain controllers with April 8, 2025 or later Windows updates",
"Monitor new audit events for affected certificates",
"Review and update altSecID mappings",
"Prepare to use only NTAuth store CAs for logon certificates"
],
"ai_master_tags": [
"Security"
],
"ai_model": "gpt-4.1",
"ai_summary": "Windows updates will enforce stricter certificate-based authentication from July 8, 2025, requiring CAs in the NTAuth store; full enforcement and policy bypass removal starts October 14, 2025.",
"ai_topics": [
"Windows",
"Entra"
],
"category": "stayInformed",
"details_map": {},
"id": "MC1111657",
"importance": 5,
"is_major_change": false,
"last_modified": "2025-07-08T17:02:41Z",
"ms_products": [
"Windows"
],
"platforms": null,
"roadmap_ids": [],
"services": [
"Windows"
],
"severity": "normal",
"tags": [
"Admin impact"
],
"title": "Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today"
}
}