Microsoft is phasing out RC4 encryption in Kerberos, the authentication protocol used by Active Directory—not removing RC4 everywhere in Windows. For on-premises domain controllers, Microsoft’s published update schedule moves from audit and preparation controls to AES-SHA1 defaults and then enforcement. Microsoft Entra Domain Services has a separate managed rollout. Older clients, services, or accounts that depend on RC4 may have authentication problems, so administrators should check their own logs and compatibility rather than assume their environment is ready.
What is Microsoft changing?
The cipher at issue is RC4 (Rivest Cipher 4), and the change covered here concerns its use in Kerberos authentication—particularly the encryption of service tickets issued by domain controllers. Microsoft’s Windows Server deprecation guidance says, “RC4 usage in the Kerberos authentication protocol is deprecated.” Deprecated does not mean that RC4 has already disappeared from every Windows configuration: Microsoft’s support guidance describes phased changes, with behavior depending on the environment, installed updates, and account settings.
This is not a blanket removal of RC4 from all Windows networking. TLS cipher suites are configured separately through Schannel and have their own documentation and controls. A change to Kerberos ticket encryption does not, by itself, establish that TLS connections using RC4 have been changed in the same way.
When does the change take effect?
Microsoft published different rollout schedules for on-premises Active Directory and Microsoft Entra Domain Services. The dates below have passed as of October 2026, but a published rollout date is not proof that a particular organization installed the relevant updates, completed migration work, or has compatible workloads.
#1 Best Overall
- 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
| Environment | Microsoft’s published phases | What administrators should verify |
|---|---|---|
| On-premises Active Directory domain controllers | Updates released on or after January 13, 2026 add audit warnings and preparation controls. Updates released on or after April 14, 2026 change the default DefaultDomainSupportedEncTypes value for KDC operations to AES-SHA1 for accounts without an explicit msds-SupportedEncryptionTypes setting. Updates released in or after July 2026 remove the temporary rollback subkey and programmatically enable the enforcement phase. |
Check which updates are installed, review account encryption settings and KDC events, and test dependent clients and services. Microsoft’s guidance covers domain controllers on Windows Server 2012 and newer; it is not limited to Server 2025. |
| Microsoft Entra Domain Services | Microsoft describes phases beginning in January 2026, enforcement with manual rollback in April, and final enforcement in July. It says RC4 was permanently disabled across all regions starting the week of July 13, 2026. | Check dependent workloads, devices, and service accounts in the managed domain, and confirm that they can use supported encryption. This managed-service schedule is distinct from the on-premises domain-controller update sequence. |
Windows Server 2025 domain controllers do not issue RC4 Ticket Granting Tickets, according to Microsoft’s Kerberos guidance. Microsoft also notes that legacy devices may still authenticate to devices with RC4 but cannot authenticate using Kerberos in that configuration. These details do not mean the wider rollout applies only to Server 2025: Microsoft’s 2026 support guidance covers multiple Windows Server versions.
Why is Microsoft phasing out RC4 in Kerberos?
Weakly encrypted service tickets can create an opportunity for offline password recovery. In a Kerberoasting attack, an attacker who can request or obtain an Active Directory service ticket may try to crack its encryption offline to recover a service account’s password. Microsoft’s CVE-2026-20833 guidance describes an information-disclosure vulnerability that might allow weak or legacy encrypted service tickets, including RC4 tickets, to be obtained for such attacks.
Rank #2
- 256 GB SSD of storage.
- Multitasking is easy with 16GB of RAM
- Equipped with a blazing fast Core i5 2.00 GHz processor.
This is a risk pathway, not a claim that every RC4 ticket leads to a compromised account. The practical security concern is that weak ticket encryption can make password-guessing attacks more useful, particularly where a service account has a guessable password. Removing RC4 dependence reduces that exposure, but it does not replace sound service-account password and access practices.
Could the change break older devices or service accounts?
Yes, a dependency on RC4 can cause authentication failures when enforcement takes effect. Possible dependencies include legacy systems, devices, services, or accounts that do not support AES-SHA1 or have encryption settings that leave RC4 in use. Microsoft’s warning is particularly relevant to non-Windows devices: the absence of certain audit events does not guarantee that every such device will accept Kerberos after an update.
Rank #3
- 14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
- Legacy clients and devices: Confirm Kerberos interoperability with the domain controllers and services they actually use; do not infer compatibility solely from a quiet audit log.
- Service accounts: Review whether accounts have an explicit
msds-SupportedEncryptionTypesvalue and whether their associated services support AES-SHA1. - Managed-domain workloads: For Entra Domain Services, inventory applications, devices, and accounts that authenticate against the managed domain before assuming they are ready for RC4 to be disabled.
Do not treat every legacy device as automatically broken, or every environment as affected identically. The outcome depends on its supported encryption, account configuration, installed updates, and authentication path.
How should administrators prepare and verify compatibility?
- Confirm the environment and update state. Separate on-premises Active Directory domain controllers from Microsoft Entra Domain Services, then verify installed updates and the applicable phase for each.
- Review KDC audit activity. Microsoft recommends monitoring the System event log for KDCSVC events 201–209 and remediating warnings and errors. Use the events to investigate reported dependencies; an absence of events is not proof that every device is compatible.
- Review ticket activity and account settings. Microsoft’s broader Kerberos guidance identifies Security event IDs 4768 and 4769 for ticket activity. Check relevant accounts’
msds-SupportedEncryptionTypessettings and determine whether their clients and services support AES-SHA1. - Test affected paths before broad enforcement. Validate authentication for non-Windows devices, legacy systems, and service-account-backed applications in the actual configuration they will use. Resolve warnings and errors before expanding enforcement.
- For Entra Domain Services, check managed-domain dependencies. Review workloads, devices, and service accounts that rely on the managed domain; do not assume the on-premises controls or rollback sequence apply to the managed service.
Microsoft’s guidance describes the relevant logs and configuration controls, but your own update state and workload tests determine whether a specific environment is ready. Follow the current Microsoft support guidance for the exact update and domain configuration in use.
Rank #4
- EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
- 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
- RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
- ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
- LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Is this the same as removing RC4 from TLS?
No. Kerberos ticket encryption and TLS cipher-suite negotiation are separate. Microsoft documents TLS cipher-suite ordering, Schannel filtering, and configuration through Group Policy, mobile device management, or TLS PowerShell cmdlets separately from the Kerberos KDC changes. Its Windows Server 2025 TLS documentation says Schannel filters RC4, DES, export, and null cipher suites when an application passes SCH_USE_STRONG_CRYPTO; that behavior should not be presented as the effect of the Kerberos rollout.
If the concern is an application’s TLS connection, investigate its TLS and Schannel configuration separately. If the concern is Active Directory tickets or KDC behavior, focus on the Kerberos guidance and the applicable domain-controller or managed-domain rollout.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Quick Recap
Best Value
- 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
- Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
- 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
- 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
- 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

