Disabling SSL 2.0, SSL 3.0, TLS 1.0 protocols in Domain Controllers

Sitaram Nayak 26 Reputation points
2021-02-25T14:14:50.097+00:00

Hi, Please help me to know if we can disable the protocols SSL 2.0, 3.0 and TLS 1.0 safely in Domain Controllers (Windows Server 2012 R2 STD 64bit operating systems) Thanks & Regards Sitaram

Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,532 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,912 questions
0 comments No comments
{count} vote

Accepted answer
  1. Dave Patrick 426.1K Reputation points MVP
    2021-02-25T16:02:11.877+00:00

    The link does mention ADFS but the steps to disable are the same. An OOB Active Directory does not require SSL/TLS

    --please don't forget to Accept as answer if the reply is helpful--

    3 people found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Daisy Zhou 18,716 Reputation points Microsoft Vendor
    2021-02-26T05:23:40.483+00:00

    Hello @Sitaram Nayak ,

    Thank you for posting here.

    Before disabling SSL 2.0, SSL 3.0 and TLS 1.0 protocols in Domain Controllers, we had better ensure all machines and apps in your AD domain do not use SSL 2.0, SSL 3.0 and TLS 1.0 protocols and all machines and apps use TLS 1.1 or TLS 1.2.

    So we can enable TLS 1.1 or TLS 1.2 and disable SSL 2.0, SSL 3.0 and TLS 1.0 protocols via GPO registry on all machines, in this way, Windows machines and Microsoft Apps should/will use TLS 1.1 or TLS 1.2.

    However, if there are third-part apps/machines with non-Windows operating system or old Apps (WIndows or non-Windows) in your AD environement, you may consider if they support TLS 1.1 or TLS 1.2 (in other word, they may only support SSL 2.0, SSL 3.0 or TLS 1.0) before disabling SSL 2.0, SSL 3.0 and TLS 1.0 protocols.

    Hope the information above is helpful.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    1 person found this answer helpful.

  2. Dave Patrick 426.1K Reputation points MVP
    2021-02-25T14:51:03.057+00:00

    You can follow along here.
    https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/manage-ssl-protocols-in-ad-fs

    --please don't forget to Accept as answer if the reply is helpful--