Category
planForChange
Severity
normal
Major change
True
Last modified
2025-09-18 23:48:54
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
—
Action by (AI)
—
Services
Microsoft 365 suite
Tags
User impact, Admin impact, Retirement
Master tags
Admin, Security, Network
Roadmap IDs
One-line summary
Microsoft 365 will enforce stricter TLS cipher suite policies, deprecating legacy suites without forward secrecy starting October 20, 2025; unsupported connections will fail.
Similar updates
More like thisMC1154299 Reminder - Support for Office 2016, Office 2019, and additional apps will end on October 14, 2025
Reminder - Support for Office 2016, Office 2019, and additional apps will end on October 14, 2025 Support for Office 2016, Office 2019, Visio 2016/2019, and Project 2016/2019 ends October 14, 2025; upgrade to Microsoft 365 Apps or Office LTSC 2024 to maintain security[What you can do to prepare:] To mitigate these risks while maintaining access.
MC1184649 Microsoft SharePoint: Retirement of IDCRL authentication protocol and enforcement of OpenID Connect and OAuth protocols
...rotocols Legacy IDCRL authentication in SharePoint Online and OneDrive for Business will be retired; legacy auth blocked Feb 16, 2026, and permanently disabled after May 1, 2026Learn more: Migrating from IDCRL authentication to modern authentication in SharePoint | Microsoft 365 Developer Blog | Microsoft Dev Blogs Set-SPOTenant.
MC1143929 Certificate-based authentication changes on Windows domain controllers - coming September 2025
Certificate-based authentication changes on Windows domain controllers - coming September 2025 Starting with September 2025 Windows updates, strict certificate mapping will be enforced on AD CS and domain controllers, blocking authentication if requirements aren't met. Since 2023, Microsoft has been sharing reminders of changes coming to.
MC1150557 Certificate-based authentication changes following installation of Windows updates released September 9, 2025
Certificate-based authentication changes following installation of Windows updates released September 9, 2025 Starting September 9, 2025, Windows updates enforce new certificate mapping requirements on Windows Servers, ending gradual rollout and requiring immediate admin action to ensure authentication works. Windows updates released September 9,.
MC1111657 Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today
Second phase for KB5057784: Protections for CVE-2025-26647 (Kerberos Authentication) begins today Windows updates will enforce stricter certificate-based authentication from July 8, 2025, requiring CAs in the NTAuth store; full enforcement and policy bypass removal starts October 14, 2025. Starting with the April 8, 2025, Windows security.
MC1092195 Prepare for Kerberos CBA changes: Enforcement begins with July updates
Prepare for Kerberos CBA changes: Enforcement begins with July updates Windows updates will enforce stricter certificate-based authentication for domain controllers, requiring CAs in the NTAuth store starting July 8, 2025, with full enforcement October 14, 2025. Starting with the April 8, 2025 Windows security updates, protections for .
Details
Summary
Microsoft 365 will deprecate legacy TLS cipher suites lacking forward secrecy on October 20, 2025, supporting only specified TLS 1.3 and 1.2 cipher suites. Organizations must update systems and configurations to maintain connectivity and security compliance.
Body (from Message Center)
[Introduction]
To strengthen encryption standards and uphold customer trust, Microsoft is deprecating support for legacy TLS cipher suites that do not offer forward secrecy. This change aligns with our ongoing commitment to security and data protection across Microsoft 365 services.
[When this will happen:]
Starting October 20, 2025, Microsoft 365 services will enforce stricter TLS cipher suite policies.
[How this affects your organization:]
Who is affected:
- Admins managing Microsoft 365 services across commercial, GCC, and GCC High tenants.
- Organizations using legacy operating systems or custom TLS configurations.
What will happen:
- Microsoft 365 services will only support the following TLS cipher suites:
- TLS 1.3
- TLS_AES_256_GCM_SHA384
- TLS_AES_128_GCM_SHA256
- TLS 1.2
- TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
- TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
- TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
- Connections using deprecated cipher suites will fail.
- Clients supporting at least one listed TLS 1.2 cipher suite will continue to connect.
- Ensure all client systems are running supported operating systems that include the required cipher suites.
- Upgrade legacy systems (e.g., Windows 8, Windows Server 2012) to supported versions.
- Review and update Group Policy or security configurations to confirm required cipher suites are enabled.
- Communicate this change to helpdesk and infrastructure teams.
- Reference the following resources for configuration guidance:
No compliance considerations identified, review as appropriate for your organization.
Raw JSON (for debugging)
Expand/collapse the full payload below.
Show/hide raw
{
"snapshot_item": {
"action_required_by": null,
"ai_action_required_by": null,
"ai_actions": [
"Upgrade legacy client and server OS",
"Enable required TLS cipher suites",
"Update Group Policy/security configs",
"Notify helpdesk and infrastructure teams"
],
"ai_master_tags": [
"Admin",
"Security",
"Network"
],
"ai_model": "gpt-4.1",
"ai_summary": "Microsoft 365 will enforce stricter TLS cipher suite policies, deprecating legacy suites without forward secrecy starting October 20, 2025; unsupported connections will fail.",
"ai_topics": [
"Microsoft 365"
],
"category": "planForChange",
"details_map": {
"Summary": "Microsoft 365 will deprecate legacy TLS cipher suites lacking forward secrecy on October 20, 2025, supporting only specified TLS 1.3 and 1.2 cipher suites. Organizations must update systems and configurations to maintain connectivity and security compliance."
},
"id": "MC1155427",
"importance": 5,
"is_major_change": true,
"last_modified": "2025-09-18T23:48:54Z",
"ms_products": [
"Microsoft 365"
],
"platforms": null,
"roadmap_ids": [],
"services": [
"Microsoft 365 suite"
],
"severity": "normal",
"tags": [
"User impact",
"Admin impact",
"Retirement"
],
"title": "Legacy TLS cipher suites will be deprecated in M365 services on October 20, 2025"
}
}