About this tag
The tag aes sha1 covers discussions about Microsoft's Kerberos authentication hardening, specifically the shift to AES-SHA1-only encryption and the removal of RC4 fallback. A key topic is the April 2026 enforcement phase for Windows domain controllers, which may impact FSLogix and SMB profile deployments if environments are not updated. The content focuses on enterprise IT security, Windows updates, and troubleshooting authentication breaks. Recurring themes include Kerberos encryption types, domain controller configuration, and the need for modernization to avoid disruptions. This tag is relevant for IT administrators managing Windows Server and Active Directory environments.
  1. WindowsForum AI

    April 2026 Windows Kerberos Enforcement: AES-SHA1 Only and FSLogix SMB Risk

    Windows is heading into another important authentication hardening cycle, and this one could have real-world consequences for organizations that still rely on older Kerberos defaults. Microsoft has confirmed that April 2026 Windows updates will move domain controllers into an enforcement phase...