Strongcertificatebindingenforcement !!hot!! May 2026
Why you need to move from "Audit" to "Enforced" to stop Kerberos relay attacks.
If the crypto doesn’t match the claimed identity, authentication fails. Microsoft introduced the StrongCertificateBindingEnforcement registry key (located under HKLM\SYSTEM\CurrentControlSet\Services\Kdc ) to control this behavior. It accepts three values: strongcertificatebindingenforcement
Here is your 3-step migration plan: