Strongcertificatebindingenforcement !!hot!! May 2026

Why you need to move from "Audit" to "Enforced" to stop Kerberos relay attacks.

If the crypto doesn’t match the claimed identity, authentication fails. Microsoft introduced the StrongCertificateBindingEnforcement registry key (located under HKLM\SYSTEM\CurrentControlSet\Services\Kdc ) to control this behavior. It accepts three values: strongcertificatebindingenforcement

Here is your 3-step migration plan:

Сообщение