Microsoft moves AD FS DKM ACL hardening to enforcement in October 2026
With the October 2026 update, Microsoft shifts AD FS DKM container ACL hardening from audit to enforcement: on Windows Server 2016 and later, insecure ACLs are remediated automatically unless RemediateDkmAcl is set to 0. The flaw, CVE-2026-56155, lets an attacker with read access to DKM key material decrypt token-signing private keys. No exploitation has been reported.
- From October 13, 2026, DKM ACL remediation in AD FS runs by default
- Windows Server 2012 and 2012 R2 require manual hardening
- CVE-2026-56155 exposes token-signing private keys
- Event 1135 records the previous ACL in SDDL, but logs can roll over
Read next
Security