ST-2026-120 · Runtime, protocol & platform support
Microsoft Entra Domain Services permanently disables Kerberos RC4
Microsoft began permanently disabling RC4 for Kerberos across Entra Domain Services regions in the week of 13 July 2026 after regional AES-only dependency tests.
Previous state
Managed domains could continue issuing Kerberos tickets or servicing LDAP binds for dependencies that required RC4.
Current state
Domain controllers enforce AES-only Kerberos as the permanent regional rollout proceeds; RC4-dependent workloads can experience Kerberos or LDAP-bind failures.
Affected users
Who needs to care
Applications, service accounts and appliances that depend on RC4 within Microsoft Entra Domain Services managed domains.
Required response
What to do
Enable security audits, identify RC4 ticket use and migrate affected accounts and workloads to supported AES encryption.
Evidence boundary
What the source does not prove
The source gives a rollout beginning in the week of 13 July rather than one universal completion timestamp. The change applies to Entra Domain Services managed domains, not every Windows or Kerberos environment.
Lifecycle history
Dated event sequence
- Americas dependency test
Managed domain controllers temporarily enforced AES-only encryption.
- Europe dependency test
The regional test included North Europe in Ireland.
- Asia-Pacific and China dependency test
The final advance test wave ran.
- Permanent rollout begins
RC4 permanent disablement began across all regions during this week.
Evidence ledger
First-party sources
- 01Microsoft Learn — RC4 deprecation advance dependency test in Microsoft Entra Domain Services
Official protocol-enforcement documentation · 2026-07-01
Open official source ↗