API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-120 · Runtime, protocol & platform support

Microsoft Entra Domain Services permanently disables Kerberos RC4

Microsoft began permanently disabling RC4 for Kerberos across Entra Domain Services regions in the week of 13 July 2026 after regional AES-only dependency tests.

Microsoft Entra Domain ServicesRC4KerberosAESLDAP

Previous state

Managed domains could continue issuing Kerberos tickets or servicing LDAP binds for dependencies that required RC4.

Current state

Domain controllers enforce AES-only Kerberos as the permanent regional rollout proceeds; RC4-dependent workloads can experience Kerberos or LDAP-bind failures.

Who needs to care

Applications, service accounts and appliances that depend on RC4 within Microsoft Entra Domain Services managed domains.

What to do

Enable security audits, identify RC4 ticket use and migrate affected accounts and workloads to supported AES encryption.

What the source does not prove

The source gives a rollout beginning in the week of 13 July rather than one universal completion timestamp. The change applies to Entra Domain Services managed domains, not every Windows or Kerberos environment.

Lifecycle history

Dated event sequence

  1. Americas dependency test

    Managed domain controllers temporarily enforced AES-only encryption.

  2. Europe dependency test

    The regional test included North Europe in Ireland.

  3. Asia-Pacific and China dependency test

    The final advance test wave ran.

  4. Permanent rollout begins

    RC4 permanent disablement began across all regions during this week.

Evidence ledger

First-party sources

  1. 01
    Microsoft Learn — RC4 deprecation advance dependency test in Microsoft Entra Domain Services

    Official protocol-enforcement documentation · 2026-07-01

    Open official source ↗