#KB5014754
Explore tagged Tumblr posts
Text
Strong Certificate Mapping Enforcement February 2025
Are you ready? In just a few short weeks(!) Microsoft will release the February 2025 security updates. This is a critical update because Microsoft plans to enable full enforcement of strong certificate mapping on Active Directory Domain Controllers (DCs) with this release. Administrators unprepared for this may incur outages for workloads using certificate-based authentication such as Always On…
View On WordPress
#AD CS#ADCS#Always On VPN#AOVPN#authentication#certificate#certificate authentication#certificate authority#certificates#Certification Authority#Cloud PKI#conditional access#enforcement#enforcement mode#Entra#Entra Conditional Access#full enforcement#InTune#KB5014754#MDM#NDES#network policy server#NPS#PKCS#PKI#PowerShell#Reason Code 16#SCEP#SID#strong certificate mapping
0 notes
Text
Intune Strong Certificate Mapping Error
Microsoft recently introduced support for strong certificate mapping in Intune to support changes introduced with the May 2022 security update KB5014754. Specifically, Intune now supports adding the SID for the principal in the subject name to the certificate for PKCS and SCEP device configuration policies. Error A few folks have contacted me about an error they encountered when configuring…
View On WordPress
#certificate#certificates#error#InTune#KB5014754#Microsoft#Microsoft Intune#OnPremisesSecurityIdentifier#PKCS#PKI#SAN#SCEP#security#strong certificate mapping#subject alternative name#update#X509
0 notes
Text
Strong Certificate Mapping for Intune PKCS and SCEP Certificates
With the October 2024 Intune update, Microsoft introduced support for strong certificate mapping for certificates issued by Intune via the Intune Certificate Connector. Enabling strong certificate mapping support in Intune is an important change for those organizations using Microsoft Intune to issue and manage certificates for their users and devices, as it resolves a critical implementation…

View On WordPress
#CA#certificate#certificate authority#certificate connector#certificates#Certification Authority#Cloud PKI#CloudPKI#domain controller#endpoint management#InTune#Intune certificate connector#KB5014754#KDC#KEYTOS#MDM#Microsoft#PKCS#PKI#SCEP#SID#strong certificate mapping#systems management#update#Windows#Windows 10#Windows 11
0 notes
Text
Azure Conditional Access Certificates with SID Information Now Available
I recently wrote about changes to certificate-based authentication affecting Always On VPN implementations. These changes were introduced by Microsoft’s security update KB5014754. When the update is installed on domain controllers and enterprise Certification Authorities (CAs), administrators can perform strong user mapping for certificates used for Active Directory authentication. However, when…
View On WordPress
#Active Directory#AOVPN#authentication#Azure#Azure AD#certificate#certificates#conditional access#endpoint manager#InTune#KB5014754#MDM#Microsoft#Microsoft Endpoint Manager#NDES#PKCS#PKI#policies#Remote Access#SCEP#security#SID#update#VPN#Windows#Windows 10#Windows 11
0 notes
Text
Certificate-Based Authentication Changes and Always On VPN
Certificate-Based Authentication Changes and Always On VPN
Microsoft introduced important changes affecting certificate-based authentication on Windows domain controllers as part of the May 10, 2022 update KB5014754 that may affect Always On VPN deployments. The update addresses privilege escalation vulnerabilities when a domain controller is processing a certificate-based authentication request. The recommendation from Microsoft is that the update be…

View On WordPress
#AD CS#AD DS#Always On VPN#AOVPN#authentication#CA#certificate#certificate mapping#certificate services#certificate template#certificates#domain controller#enterprise mobility#hotfix#KB5014754#Microsoft#Mobility#OID#PKI#Remote Access#secure remote access#security#SID#template#update#Windows#Windows 10#Windows 11
0 notes