Protections for CVE-2025-26647 (Kerberos Authentication) - Microsoft Support

ComputerHabit 1,066 Reputation points
2025-04-30T19:59:46.2433333+00:00

Microsoft please tell us what to do.

You don't tell us what you want. Why won't you just say what to do in the article you send to millions?

Protections for CVE-2025-26647 (Kerberos Authentication) - Microsoft Support

It makes no sense to tell us to do something but give no detail on what to do.

Windows for business | Windows Server | User experience | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Chen Tran 12,750 Reputation points Independent Advisor
    2025-08-08T11:04:35.17+00:00

    Hello,

    Thank you for posting question on Microsoft Windows Forum!

    Based on the information in your provided link Protections for CVE-2025-26647 (Kerberos Authentication) - Microsoft Support. It indicates that Microsoft added protections for a Kerberos elevation-of-privilege issue. The rollout into three phases, starts in Audit mode, then becomes enforced by default, and later removes the bypass.

    Key dates you must plan around.

    • April 8, 2025: Updates introduce Audit mode (no enforcement unless you explicitly enable it).
    • July 8, 2025: Enforcement by default begins; you can still temporarily roll back to Audit via the registry setting.
    • October 14, 2025: The bypass is removed; all logon certificates must be issued by CAs in the NTAuth store.
    • If you need to change behavior before those phases, you must manually create the registry setting—it's not created automatically—and only do this on Windows KDCs (your DCs).

    You can refer to the following articles for more information.

    Hope the above information is helpful!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.