Microsoft identity-related security enforcement is changing across both on-prem AD and cloud Entra environments, with potential authentication and access-control impacts if organizations have legacy configurations. In Windows Server 2025, LDAP signing is enabled by default on domain controllers via a new policy setting (LDAP server signing requirements Enforcement), while LDAP channel binding default behavior is unchanged; organizations are advised to audit before enforcing to avoid breaking LDAP-dependent applications and integrations.
Separately, Microsoft Entra will change Conditional Access enforcement starting March 27, 2026 (phased through June 2026) for sign-ins via client apps requesting only OIDC scopes or a limited set of directory scopes when Conditional Access targets All resources and includes resource exclusions. After the change, Conditional Access will be enforced at sign-in even when exclusions exist, which may newly trigger controls such as MFA or device compliance for affected tenants; tenants without “All resources” policies that include exclusions are not impacted.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The phased rollout window for the Entra Conditional Access enforcement change is scheduled to run through June 2026, marking the expected completion period for the update across affected tenants.
Microsoft said the Conditional Access enforcement change in Entra will begin rolling out on March 27, 2026, and continue in phases through June 2026. Only tenants with policies targeting all resources and one or more resource exclusions are affected.
Microsoft announced that Conditional Access policies targeting 'All resources' with resource exclusions will be enforced at sign-in for certain client applications requesting only OIDC or limited directory scopes. The change can trigger new controls such as MFA or device compliance checks for affected tenants.
With Windows Server 2025 domain controllers, Microsoft introduced the 'LDAP server signing requirements Enforcement' policy so that leaving it 'Not Configured' results in 'Require Signing,' effectively enabling LDAP signing by default. LDAP channel binding defaults were not changed and remain disabled unless explicitly configured.
Microsoft's August 8, 2023 update KB4520412 for Windows Server 2019 and 2022 domain controllers added additional telemetry for LDAP channel binding failures, improving visibility into non-compliant LDAPS clients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.