Microsoft

Microsoft prepares RC4 shutdown with Windows update

The January 2026 updates will begin the phaseout of RC4 encryption in the Kerberos protocol for Windows Server. The trigger is a security flaw that allows attackers to request Kerberos service tickets using weak algorithms.

Security flaw forces AES switch

As a result, offline attacks are possible to read passwords from service accounts and gain unauthorized network access. All Windows Server versions from 2008 up to and including Windows Server 2025 are affected. Microsoft therefore announced some time ago that security hardening was coming. The aim is to exclusively use modern AES encryption in Active Directory. In the current phase, which started with the January patch day, the updates initially only activate monitoring functions such as Günter Born now writes in his blog.

Systems that continue to use RC4 will be recorded in the event log without blocking connections. This gives administrators time to identify outdated devices and applications, such as older multifunction printers, NAS systems or legacy software without AES support. Like Microsoft in explained in a support document this “Initial Deployment Phase” serves to prepare for further steps. The group provides the registration key RC4DefaultDisablementPhase for tests. This means that RC4 deactivation can be brought forward as soon as the logs no longer show any warning messages. The schedule envisages a gradual tightening.

Tough schedule until summer 2026

The second phase will begin in April 2026: domain controllers will only accept AES algorithms by default. The `DefaultDomainSupportedEncTypes` attribute is adjusted accordingly unless explicit exceptions are set. Devices or applications that do not support these methods will then no longer be able to establish connections, which can cause login or access problems. The final phase will follow in July 2026. With the updates, the so-called enforcement mode will be activated. Transitional solutions such as monitoring mode or registry exceptions are no longer necessary. Connections with RC4 are then consistently blocked.

Background: The end of an era for RC4

The RC4 stream cipher was developed by Ron Rivest in 1987 and was widely used for a long time. Despite known weaknesses, it remained in use in many legacy systems for compatibility reasons. However, in protocols such as WEP and SSL/TLS, RC4 has been considered insecure for years and is no longer supported. According to Microsoft, the vulnerability CVE-2026-20833 shows that supporting outdated encryption poses a security risk for entire Active Directory environments. Attacks targeting RC4’s weaknesses can expose plaintext information, compromising domain security.

Recent Posts

Mouse for MMO players: Razer’s new Naga V3 Pro is a button monster

Razer is launching a new MMO mouse with the Naga V3 Pro. Three magnetic side…

6 hours ago

Surface Phone: New images show discarded Microsoft prototype

It's an open secret that Microsoft was working on a Windows Phone smartphone long before…

6 hours ago

How Solar Carport Structures Are Changing the Future of Sustainable Energy Infrastructure

As the demand for renewable energy continues to grow, businesses, municipalities, and property owners are…

7 hours ago

What to do to find the right family law support in your case.

Family law issues seldom come at an opportune moment. Divorce, separation, parenting conflicts, child support,…

7 hours ago

Claude AI data leak: Private chats were freely accessible on Google

Due to an insufficiently protected sharing function, private chat logs from the Anthropic AI Claude…

23 hours ago

Mark Zuckerberg’s megayacht Launchpad ignored calls for help off Alaska

Mark Zuckerberg's $300 million superyacht ignored or allegedly did not hear a call for help…

23 hours ago