Anyone dealing with KB5014754 and the May 10, 2022, update KB5013944?
I manage a small environment with less than 100 users and have a redundant pair of Sever 2022 domain controllers. For the users in AD, I use password-based authentication - no certificates. I checked certmgr and did not find any references under "personal" either.
The DC's were migrated from 2012 R2 in Aug / September of 2023 and I do not have the May 10, 2022 update installed. I would have expected that the May 10,2022 update would be installed under a subsequent cumulative. However, since I do not have the strongcertificatebindingenforcement registry key, I concluded that the May 10, 2022 update has not been installed. Servers are patched until the recent Jan 2025 updates.
I'm leaning towards caution with a view that less is better. The question I ask is if no certificate-based authentication used in the environment, does this use case for KB 5014754 applies.
Should I leave the environment as-is, since my understanding is that Microsoft is not mandating certificate-based authentication at this time or am I at risk if I do nothing.
Any suggestions, recommendations would be highly appreciated.
TIA
I manage a small environment with less than 100 users and have a redundant pair of Sever 2022 domain controllers. For the users in AD, I use password-based authentication - no certificates. I checked certmgr and did not find any references under "personal" either.
The DC's were migrated from 2012 R2 in Aug / September of 2023 and I do not have the May 10, 2022 update installed. I would have expected that the May 10,2022 update would be installed under a subsequent cumulative. However, since I do not have the strongcertificatebindingenforcement registry key, I concluded that the May 10, 2022 update has not been installed. Servers are patched until the recent Jan 2025 updates.
I'm leaning towards caution with a view that less is better. The question I ask is if no certificate-based authentication used in the environment, does this use case for KB 5014754 applies.
Should I leave the environment as-is, since my understanding is that Microsoft is not mandating certificate-based authentication at this time or am I at risk if I do nothing.
Any suggestions, recommendations would be highly appreciated.
TIA