Updated March 20, 2026: Added additional guidance for devices using Azure Files SMB with Active Directory–based authentication and Azure Virtual Desktop. Windows updates released April 2026 and later introduce the second deployment phase of protections for a Kerberos information disclosure vulnerability (CVE‑2026‑20833). In this phase, domain controllers change default Kerberos ticket behavior for accounts that do not have an explicit Kerberos encryption configuration, shifting to AES‑SHA1-only...
Applies to: Windows
Source: mc.merill.net — data via Merill Fernando's open archive (MIT).