The recent April Patch Tuesday updates have brought an unexpected challenge for enterprise administrators and IT security professionals: broken Kerberos authentication for Windows Hello and certificate-based logins on Active Directory Domain Controllers (DC) running supported versions of Windows...
active directory
ad domain controllers
authentication security
certificatetrustcertificate-based logons
cve-2025-26647
enterprise identity
enterprise it
it security
kerberos authentication
kerberos delegation
ntauth store
passwordless authentication
patch tuesday
pki management
pkinit
security vulnerabilities
smart card login
windows hello for business
windows server
Over the past several years, Windows Hello for Business (WHfB) has emerged as a cornerstone of Microsoft’s modern authentication approach, prioritizing both convenience and layered security. However, recent developments have drawn fresh scrutiny to the ecosystem’s dependence on complex trust...
active directory
certificate chain validation
certificatetrust
cve-2025-26647
device authentication
enterprise authentication
kerberos authentication
kerberos delegation
microsoft kb articles
ntauth store
passwordless authentication
patch tuesday
pki management
pkinit
security patches
smartcard sso
trust relationships
windows hello for business
windows security updates
windows server
It was just over one year ago, May 28, 2012, to be exact, that I transitioned from running active MSRC cases and writing bulletins to my current role managing software security incidents. A lot has changed in that year - and I’ve dealt with some interesting issues during my tenure - but...
certificatetrust
cryptography
cumulative updates
customer protection
deployment priority
digital certificates
internet explorer
june 2013
microsoft office
pki
remote code execution
security
security advisories
software security
trustworthy computing
update management
vulnerabilities
windows 7
windows updates
windows vista