RC4 Deprecation in Active Directory: Timeline and Phases
Microsoft's 2026 rollout for RC4 in Kerberos: phase dates, the AES default for unspecified accounts, legacy services to verify, and an operational migration path that avoids outages.
Analytics preferences
I use GA4 only for aggregated traffic and CTA analytics, without advertising purposes.
Field Guides
How-tos, real-world troubleshooting, and field notes from identity architecture programs.
Browse by topic
Filter all guides by topic.
12 published guides
Microsoft's 2026 rollout for RC4 in Kerberos: phase dates, the AES default for unspecified accounts, legacy services to verify, and an operational migration path that avoids outages.
A runbook for safely rotating the KRBTGT password: prerequisites, replication, double reset, Kerberos validation, operational rollback, and telemetry.
An operational path to measure real NTLM usage, separate legitimate dependencies from misconfigured Kerberos fallbacks, and reach progressive blocking with rollback criteria.
Protected Users in Active Directory is a hardening control for human admin accounts: learn what it blocks, how adminCount works, and how to roll it out without lockout.
Practical Active Directory lab: can a legacy RC4-only service account issue AES Kerberos tickets after a pwdLastSet toggle and msDS-SupportedEncryptionTypes change, without a password reset?
Practical SPN guide for Active Directory: real failure patterns, missing/duplicate SPNs, KCD/RBCD edge cases, key Event IDs, and a remediation path to reduce NTLM fallback.
Kerberos-to-NTLM fallback is not a compatibility detail: it is usually the symptom of a missing SPN, an IP-based connection, a misconfigured service, or a legacy dependency the environment has not surfaced yet. This article shows how to recognize it, why Protected Users makes it visible, and which real-world cases to fix first.
Operational guide on GPO Enforced and Block Inheritance in Active Directory: how they really work, what mistakes they create in production, and how to manage exceptions, rollback, and governance without triggering policy drift.
Expected NTFS and Share permissions on SYSVOL and NETLOGON, difference between nominal and effective permissions, common drift patterns in enterprise environments, and PowerShell commands for verification and remediation without impacting DFSR replication.
Practical guide to GPO Security Filtering and Delegation in Active Directory: how to separate targeting from administration to avoid audit, hardening, and governance mistakes.
How to assess Active Directory Group Policy security by reviewing SYSVOL NTFS and Share ACLs. Includes a real scenario, audit checklist, PowerShell commands, and operational remediation.
If this were my company, I would not start with the loudest finding: I would start with real exposure, blast radius, dependencies, and clear proof that risk decreased.