
Microsoft’s July 2026 Windows security update has moved Active Directory domain controllers into the final enforcement phase for protections linked to CVE-2026-20833. The Windows updates from July 2026 remove Audit mode and stop reading the temporary RC4DefaultDisablementPhase rollback setting. Workloads that relied on RC4 being assumed when no encryption type was explicitly configured may now experience Kerberos authentication failures. This does not remove every administrator-configured use of RC4, but it ends the old implicit fallback.
What changed in July 2026
The update addresses an information disclosure weakness that could allow attackers to obtain service tickets using weaker encryption, including RC4, and attempt to recover service account passwords offline. Microsoft introduced the change in stages. Updates from 13 January 2026 added KDC audit events. From 14 April, domain controllers defaulted to AES-SHA1 for accounts without an explicit msDS-SupportedEncryptionTypes value, while administrators could still use a temporary rollback. The July update makes enforcement the only supported phase.
RC4 itself has not vanished from every configuration. An account or domain controller that has been explicitly configured to allow it may continue to do so, although Microsoft warns that this remains insecure. The main risk is to clients that advertise only RC4, service accounts that lack AES keys and non-Windows integrations that use old RC4-only keytabs.
What could break and what to do
| What could break | Why it is at risk | What to do |
|---|---|---|
| Service accounts used by SQL Server, IIS application pools or scheduled tasks | The account has no explicit encryption setting, lacks AES keys or supports only RC4 | Confirm application support for AES, reset the account password to generate modern keys where appropriate, and configure the supported encryption types correctly |
| Non-Windows appliances, NAS devices and line-of-business systems | The device advertises only RC4 or uses a keytab exported with RC4 keys only | Update the product, re-export the keytab with AES keys and test authentication with the vendor |
| Windows Server 2003 and similarly old platforms | These systems do not support AES-SHA1 Kerberos encryption | Replace or isolate the system and plan a supported migration |
Domains with DefaultDomainSupportedEncTypes explicitly allowing RC4 | The July change honours the explicit setting, leaving the domain exposed | Move to an AES-only setting after confirming that dependent systems have been remediated |
How to find affected accounts
Start with the System event log on every patched domain controller. Microsoft added KDCSVC events 201 to 209 to identify clients that advertise insecure encryption, services without AES keys and unsafe domain-wide settings. Events 201 and 202 are warnings seen during auditing, while 203, 204, 208 and 209 indicate blocked or denied requests in enforcement. Event 205 highlights an explicit insecure DefaultDomainSupportedEncTypes configuration.
Microsoft’s detection guidance also explains how to examine security events 4768 and 4769 and provides scripts for identifying remaining RC4 use. Do not rely only on the absence of warnings. Microsoft says non-Windows interoperability must be tested because some failures occur at the target service rather than at the KDC.
A current asset inventory, regular vulnerability management and routine vulnerability scanning can help locate forgotten appliances and servers before users discover the problem.
Treat RC4 exceptions as temporary
Where a critical third-party system cannot yet use AES, Microsoft permits an explicit RC4 configuration on the affected service account as a temporary compatibility measure. This should be tightly scoped and recorded because it preserves exposure to RC4-based Kerberoasting.
A managed SOC service can monitor relevant authentication events, while MDR services add investigation and response when activity looks malicious. Cyber security awareness training also remains important because compromised credentials can provide the initial foothold.
Systems that have reached end of support should be replaced rather than protected indefinitely with an RC4 exception. Authentication failures can interrupt file access, applications and scheduled processes, so test changes against a documented business continuity plan.
The July 14, 2026 security update is already available. If it has not yet been deployed to every domain controller, use the remaining rollout window to monitor, test and remediate dependencies first. Northern Star’s managed IT support services in London can help identify RC4 use, move compatible accounts to AES and plan replacements without an avoidable outage. Call 0800 319 6032 to get started.
Focus on Active Threat Defense and Infrastructure Management
Securing a modern enterprise demands continuous vigilance across every device, server, and cloud network. The engineering experts at Northern Star design tailored environments using London Microsoft Azure services and integrated London Microsoft 365 solutions. We also implement Microsoft Copilot consulting for AI efficiency, while reinforcing safety protocols with customized cybersecurity training and robust email security in London.
Beyond user safety, we secure your perimeter by resolving weaknesses using vulnerability management in London. Our 24/7 managed security operations center works alongside proactive managed detection and response in London to intercept threats. Should an outage occur, our cyber incident response services and structured business continuity planning guarantee rapid recovery. Get in touch with us today.












