Starting in April 2026, Windows updates will change the default Kerberos ticket issuance behavior to AES-SHA1 for accounts without...
Tag Archive for: encryption
4sysops - The online community for sys and AI ops
New SMTP DANE and MTA-STS connector modes in Exchange Online
Exchange Online now lets you choose, per outbound connector, whether SMTP DANE and MTA-STS are enforced opportunistically, mandatorily (for...
Using OpenID Connect (OIDC) for external MFA in Entra ID
Microsoft has introduced external Multi-Factor Authentication (MFA) as the new, fully integrated OpenID Connect (OIDC)-based way to connect third-party...
Update Windows Secure Boot DB certificates with Group Policy and PowerShell
Microsoft's original Secure Boot certificates from 2011 begin expiring in June 2026. Windows devices that still rely on these...
Monitoring Secure Boot certificate installation status with Intune and PowerShell
Microsoft Secure Boot certificates issued by the 2011 Certificate Authorities (CAs) are expiring starting June 2026. Every Windows device...
Update Secure Boot certificates on Windows Server and VMs before June 2026
Microsoft's original Secure Boot certificates — issued in 2011 — begin expiring in June 2026. Unlike Windows 11, Windows...
How to manage Microsoft Cloud PKI certification authority (CA) expiration in Intune
Microsoft Cloud PKI for Intune automates certificate management for enrolled devices, but you must manually handle the expiration of...
Disable weak RC4 encryption on Active Directory domain controllers to prevent Kerberoasting attacks exploiting Kerberos vulnerability CVE-2026-20833
Microsoft has initiated a critical security hardening phase for Windows Active Directory domain controllers to address CVE-2026-20833, a Kerberos...
Windows Secure Boot certificates expire in 2026
Microsoft has started automatically updating Secure Boot certificates on eligible Windows 11 systems with the January 2026 security update....
Outlook cannot open encrypted emails
Microsoft 365 users face a critical bug in Classic Outlook that prevents recipients from opening encrypted emails. In Classic...
Hardware-accelerated BitLocker encryption using SoC crypto engines in Windows 11
Microsoft introduced hardware-accelerated BitLocker to address the performance overhead of disk encryption on modern high-speed NVMe drives. This feature...
Sending encrypted emails with Gmail Client-side Encryption (CSE) to external recipients
On October 2, 2025, Google announced that Gmail Client-side Encryption (CSE) now enables Google Workspace Enterprise Plus users with...
Migrate Certification Authority to Windows Server 2025
In an earlier article, I discussed migrating an Active Directory domain controller to Windows Server 2025. This article explains...
Enable Device Encryption on Windows 11
Device Encryption is a Windows feature that automatically enables BitLocker-based encryption on the system drive and other fixed drives,...
Disable BitLocker on Windows 11
Several reasons exist for wanting to turn off BitLocker on an individual machine or across your network. In Windows...
AI-powered anomaly detection with ManageEngine Ransomware Protection Plus
Cyberattackers are evolving their tactics and developing more sophisticated ransomware. Advanced AI-driven security solutions are needed to provide the...
Recover data from corrupted BitLocker drives with repair-bde and key packages
Activating BitLocker encryption on a drive automatically generates a 48-digit numeric recovery password. This password is crucial if other...
Unlock BitLocker drive from Windows PE with a PowerSell script
BitLocker can pose a significant challenge when multiple PCs need to be booted from an external drive for troubleshooting....
Install Let’s Encrypt certificates on Windows with Certbot and export as PFX
Let's Encrypt offers free certificates that are only valid for 90 days. Because manually renewing them every three months...
Rotate BitLocker recovery passwords, delete used keys from Active Directory
For security reasons, it makes sense to replace the recovery password used to unlock an encrypted drive each time...


.png)

.png)

.png)


.png)













