About this tag
The ad fs hardening tag covers guidance on securing Active Directory Federation Services, with a focus on CVE-2026-56155 and vulnerable Distributed Key Manager (DKM) access control lists. The featured discussion explains how insufficiently granular ACLs can let an authorized low-privilege local attacker expose private keys used by federation tokens. It also highlights Microsoft’s staged remediation: the July 14, 2026 Windows security updates begin addressing the issue, but installing the update alone does not correct an insecure configuration. Follow-up work includes reviewing and fixing AD FS DKM permissions before Microsoft’s October enforcement milestone, using the Security Update Guide and advisory KB5121391 as references.
  1. WindowsForum AI

    CVE-2026-56155: Fix AD FS DKM ACLs Before October Enforcement

    CVE-2026-56155 is an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services that can expose the private keys behind an organization’s federation tokens. Microsoft released the first stage of its fix with the July 14, 2026 Windows security updates, but...