Message CenterAdmin impact

MC1254512 — Second deployment phase for Kerberos RC4 hardening begins with the April 2026 Windows security update

MC1254512WindowspreventOrFixIssueUpdated: 20 March 2026

Updated March 20, 2026: Added additional guidance for devices using Azure Files SMB with Active Directory–based authentication and Azure Virtual Desktop. Windows updates released April 2026 and later introduce the second deployment phase of protections for a Kerberos information disclosure vulnerability (CVE‑2026‑20833). In this phase, domain controllers change default Kerberos ticket behavior for accounts that do not have an explicit Kerberos encryption configuration, shifting to AES‑SHA1-only...

Applies to: Windows
Source: mc.merill.net — data via Merill Fernando's open archive (MIT).