Microsoft’s history with Windows updates has often been punctuated by instances where critical security patches—introduced to defend against real-world threats—have triggered unexpected issues in enterprise environments. The April 2025 Patch Tuesday release is one such event, and its fallout has...
active directory
authentication
certificate validation
certificate-based logon
domain controller
enterprise security
event log
kerberos authentication
kerberos vulnerabilities
ntauth store
patch
pkipkinit
registry tweaks
security best practices
security updates
windows security
windows server
windows troubleshooting
windows update
The recent April Patch Tuesday updates have brought an unexpected challenge for enterprise administrators and IT security professionals: broken Kerberos authentication for Windows Hello and certificate-based logins on Active Directory Domain Controllers (DC) running supported versions of Windows...
active directory
authentication
certificate
certificate-based logons
cve-2025-26647
domain controller
enterprise identity
enterprise it
kerberos authentication
kerberos delegation
ntauth store
passwordless authentication
patch
pkipkinit
security
smart card authentication
vulnerabilities
windows hello for business
windows server
Over the past several years, Windows Hello for Business (WHfB) has emerged as a cornerstone of Microsoft’s modern authentication approach, prioritizing both convenience and layered security. However, recent developments have drawn fresh scrutiny to the ecosystem’s dependence on complex trust...
active directory
certificate
certificate validation
cve-2025-26647
device authentication
enterprise authentication
kerberos authentication
kerberos delegation
microsoft kb articles
ntauth store
passwordless authentication
patch
pkipkinit
security updates
smartcard sso
trust relationship
windows hello for business
windows security updates
windows server
In today's interconnected world, where safeguarding digital assets and maintaining trust are paramount, the marriage of DigiCert ONE and Microsoft Azure couldn't come at a better time. DigiCert, a titan in the domain of digital trust and public key infrastructure (PKI), has strategically aligned...
Revision Note: V1.2 (September 5, 2012): Corrected the common name for the "CN=Microsoft Online Svcs BPOS APAC CA4" certificate issued by Microsoft Services PCA.
Summary: Microsoft is aware of Microsoft certificate authorities that are outside our recommended secure storage practices. Upon a...
It was just over one year ago, May 28, 2012, to be exact, that I transitioned from running active MSRC cases and writing bulletins to my current role managing software security incidents. A lot has changed in that year - and I’ve dealt with some interesting issues during my tenure - but...
certificate
consumer protection
cryptography
cumulative update
deployment priority
digital certificates
internet explorer
june 2013
microsoft office
pki
remote code execution
security
security advisories
software security
trustworthy computing
update management
vulnerabilities
windows 7
windows update
windows vista
Troubleshoot Windows Directory PKI and ADCS issues by using this diagnostic service from Microsoft. This troubleshooter is integrated with the Microsoft Fix It Center Pro service. This service can perform automated diagnostic analysis to identify...
Link Removed
Hello there. As we prepare for September’s two security updates, we’d like to remind you about an important change to Windows’ certificate requirements included in Security Advisory 2661254 (Update For Minimum Certificate Key Length). In June, we began communicating this...
activex
asset inventory
certificate
configuration manager
encryption
key length
microsoft
october update
pki
public key infrastructure
rsa
s/mime
security
security advisory
ssl
threats
trusted internet
update
visual studio
windows
Before we dive into the July security updates, let’s change up the normal order and take a look at the two Security Advisories we are releasing today. One takes an exciting step into the future, while the other prepares us to take an equally important step away from the past.
Security...
advisories
certificate
code signing
critical update
deployment
digital certificates
gadgets
housekeeping
internet explorer
management
microsoft
microsoft store
pki
remote code execution
risk management
security
update
vulnerabilities
windows 7
windows vista
Revision Note: V1.0 (July 10, 2012): Advisory published.
Summary: Microsoft is aware of Microsoft certificate authorities that are outside our recommended secure storage practices. Upon a routine review, we are placing these certificates in the Untrusted Certificate Store, and...