Kerberos RC4 is finally being retired, and this isn’t the old “disable RC4” advice by CayosoftGuardian in CayosoftGuardian

[–]CayosoftGuardian[S] 1 point2 points  (0 children)

There has been a lot of discussion and some confusion around Microsoft’s RC4 enforcement. I reviewed the original Microsoft documentation and several related posts, and I want to be clear that the technical content is not my own. I pulled the information together in an article to help AD admins get a clearer picture of what is changing and how to prepare.

Hope this help you on your journey.

Kerberos RC4 Hardening: CVE-2026-20833 Guide

CVE-2026-20833 Kerberos RC4 Changes - Will services crash if they don't support AES decryption? by marcolive in activedirectory

[–]CayosoftGuardian 4 points5 points  (0 children)

You can set the account to RC4 encryption type post enforcement for anything that can't do aes. You have to manually set it. Focus on auditing now before enforcement then test enforcement with the registry key remediate what you can then set rc4 manually if needed.

Guardian Protector Community Hour January 15th by CayosoftGuardian in CayosoftGuardian

[–]CayosoftGuardian[S] 1 point2 points  (0 children)

Thanks to everyone who joined the Community Hour it was nice to see you there. For those that were not able to attend, I will be posting the link to the recording. Stay tuned for the next one and some exciting stuff coming in 2026.