#KB5014754
Explore tagged Tumblr posts
richardmhicks · 5 months ago
Text
Strong Certificate Mapping Enforcement February 2025
Are you ready? In just a few short weeks(!) Microsoft will release the February 2025 security updates. This is a critical update because Microsoft plans to enable full enforcement of strong certificate mapping on Active Directory Domain Controllers (DCs) with this release. Administrators unprepared for this may incur outages for workloads using certificate-based authentication such as Always On…
Tumblr media
View On WordPress
0 notes
richardmhicks · 8 months ago
Text
Intune Strong Certificate Mapping Error
Microsoft recently introduced support for strong certificate mapping in Intune to support changes introduced with the May 2022 security update KB5014754. Specifically, Intune now supports adding the SID for the principal in the subject name to the certificate for PKCS and SCEP device configuration policies. Error A few folks have contacted me about an error they encountered when configuring…
Tumblr media
View On WordPress
0 notes
richardmhicks · 8 months ago
Text
Strong Certificate Mapping for Intune PKCS and SCEP Certificates
With the October 2024 Intune update, Microsoft introduced support for strong certificate mapping for certificates issued by Intune via the Intune Certificate Connector. Enabling strong certificate mapping support in Intune is an important change for those organizations using Microsoft Intune to issue and manage certificates for their users and devices, as it resolves a critical implementation…
Tumblr media
View On WordPress
0 notes
richardmhicks · 2 years ago
Text
Azure Conditional Access Certificates with SID Information Now Available
I recently wrote about changes to certificate-based authentication affecting Always On VPN implementations. These changes were introduced by Microsoft’s security update KB5014754. When the update is installed on domain controllers and enterprise Certification Authorities (CAs), administrators can perform strong user mapping for certificates used for Active Directory authentication. However, when…
Tumblr media
View On WordPress
0 notes
richardmhicks · 3 years ago
Text
Certificate-Based Authentication Changes and Always On VPN
Certificate-Based Authentication Changes and Always On VPN
Microsoft introduced important changes affecting certificate-based authentication on Windows domain controllers as part of the May 10, 2022 update KB5014754 that may affect Always On VPN deployments. The update addresses privilege escalation vulnerabilities when a domain controller is processing a certificate-based authentication request. The recommendation from Microsoft is that the update be…
Tumblr media
View On WordPress
0 notes