← Back
Certificate-based authentication changes following installation of Windows updates released September 9, 2025
MC1150557 · build prod-20251231-200323
Category
planForChange
Severity
normal
Major change
True
Last modified
2025-09-09 17:07:04
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Windows
Tags
Admin impact
Master tags
Security
Roadmap IDs

One-line summary

Starting September 9, 2025, Windows updates enforce new certificate mapping requirements on Windows Servers, ending gradual rollout and requiring immediate admin action to ensure authentication works.

Similar updates

More like this
MC1143929 Certificate-based authentication changes on Windows domain controllers - coming September 2025
Certificate-based authentication changes on Windows domain controllers - coming September 2025 Starting with September 2025 Windows updates, strict certificate mapping will be enforced on AD CS and domain controllers, blocking authentication if requirements aren't met. The final milestone o... For full details, see KB5014754: Certificate-based.
MC959496 Full Enforcement mode for certificate-based authentication on Windows DCs effective February 2025
This mode change occurs when you install the Windows updates dated February 2025 or later. Starting in May 2022, certificate-based authentication on Windows DCs started to go through a series of changes to enhance security, following a planned timeline of Enablement Phases. For full details, see KB5014754. ...forcement  registry value will no.
MC1096052 Windows add support for the new certificate authority handling logic in Application Control for Business
Windows add support for the new certificate authority handling logic in Application Control for Business Application Control for Business updates CA trust logic to handle expiring Microsoft CAs, requiring Windows updates by May 13, 2025 for seamless trust extension. Microsoft is updating the logic used by Application Control for Business to.
MC1092195 Prepare for Kerberos CBA changes: Enforcement begins with July updates
Prepare for Kerberos CBA changes: Enforcement begins with July updates Windows updates will enforce stricter certificate-based authentication for domain controllers, requiring CAs in the NTAuth store starting July 8, 2025, with full enforcement October 14, 2025. Starting with the April 8, 2025 Windows security updates, protections for .
MC1111657 Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today
Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today Windows updates will enforce stricter certificate-based authentication from July 8, 2025, requiring CAs in the NTAuth store; full enforcement and policy bypass removal starts October 14, 2025. Starting with the April 8, 2025, Windows security.
MC1139443 Secure Boot certificate expiration: What Windows IT admins need to know now
Secure Boot certificate expiration: What Windows IT admins need to know now Microsoft is updating Secure Boot certificates before current ones expire in 2026; IT admins must ensure systems accept new certificates to maintain security and updates. Secure Boot protects Windows systems by validating firmware and boot components using trusted ce....

Details

Body (from Message Center)

Windows updates released September 9, 2025 and later, introduce security hardening changes to certificate mapping requirements in Windows Servers. The is the final milestone of a rollout that has gradually been taking place since 2023. IT administrators need to take action to ensure normal operations in accordance with the new certificate mapping criteria, and install the September 9, 2025 updates.

For full details, see KB5014754: Certificate-based authentication changes on Windows domain controllers.

When will this happen:
This change is effective immediately in Windows updates released September 9, 2025. Servers which run Active Directory Certificate Services, as well as Windows domain controllers that service certificate-based authentication, are now required to meet certain certificate mapping criteria in order for authentication operations to succeed. These changes address vulnerabilities discussed in CVE-2022-34691 and others.

How this will affect your organization:
Vulnerabilities addressed in this scenario involve the use of dollar sign ($) at the end of a machine name, as well as conflicts between User Principal Names (UPN) and sAMAccountName. Both scenarios introduced vulnerabilities in the form of certificate emulation (spoofing).

The September 2025 updates conclude the rollout of security requirements which prevent these vulnerabilities. If certificates cannot be strongly mapped per the security measures following installation of this update, certain authentication operations might be denied.

What you need to do to prepare:
The new certificate mapping requirements mentioned here have been rolling out with various degrees of enforcement throughout 2023 and 2024. Beginning with the September 9 updates, previous methods of grading enforcement across environments have been disabled. IT administrators need to confirm normal operations in accordance with the new certificate mapping criteria.

As always, we recommend that you update your devices to the latest security update available to take advantage of the advanced protections from the latest security threats. Review the links provided in the Additional information section.

Additional information:

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Install September 9, 2025 Windows updates",
      "Verify certificate mapping compliance",
      "Review KB5014754 for details"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "Starting September 9, 2025, Windows updates enforce new certificate mapping requirements on Windows Servers, ending gradual rollout and requiring immediate admin action to ensure authentication works.",
    "ai_topics": [
      "Windows",
      "Windows Server"
    ],
    "category": "planForChange",
    "details_map": {},
    "id": "MC1150557",
    "importance": 5,
    "is_major_change": true,
    "last_modified": "2025-09-09T17:07:04Z",
    "ms_products": [
      "Windows"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Windows"
    ],
    "severity": "normal",
    "tags": [
      "Admin impact"
    ],
    "title": "Certificate-based authentication changes following installation of Windows updates released September 9, 2025"
  }
}