SHD / MC Checker

MC1442510 | 90-Day Reminder: AD FS DKM container ACL hardening begins in October 2026



MC1442510 | 90-Day Reminder: AD FS DKM container ACL hardening begins in October 2026

Classification stayInformed
Last Updated 07/29/2026 21:03:07
Start Time 07/29/2026 21:03:06
End Time 07/29/2027 21:03:06
Message Content
What and why
Windows updates released in October 2026 will begin Enforcement mode for AD FS Distributed Key Manager (DKM) container ACL hardening. This change is designed to address the elevation of privilege vulnerability documented in CVE-2026-56155 by automatically remediating insecure DKM container ACL configurations on supported Windows Server versions.
Organizations using Active Directory Federation Services (AD FS) should use the current Audit mode period to review DKM container permissions and identify potential compatibility issues before enforcement begins.
Rollout schedule
Enforcement mode begins with the October 2026 Windows security update.
Impact on your organization
Organizations using AD FS might experience changes to DKM container permissions when remediation is applied during Enforcement mode. Starting with the October 2026 update, remediation will run by default on supported Windows Server versions unless administrators explicitly opt out. Windows Server 2012 and Windows Server 2012 R2 require manual remediation and are not automatically remediated.
Action required/recommendations
Organizations using AD FS should:
  • Install the July 2026 Windows security update or a later Windows update on AD FS servers.
  • Review AD FS Admin event logs for Event ID 1132, which indicates that DKM container permissions require attention.
  • Review and test remediation during the current Audit mode phase before Enforcement mode begins in October 2026.
  • Review the guidance in: CVE-2026-56155: AD FS Distributed Key Manager container ACL hardening.
Compliance considerations
No compliance considerations are identified. Review as appropriate for your organization.
Machine Translation
何となぜ
2026年10月にリリースされたWindowsアップデートは、AD FS分散キーマネージャ(DKM)コンテナのACLハードニングの強制モードを開始します。この変更は、サポートされるWindows Serverバージョンで安全でないDKMコンテナACL構成を自動的に補正することで、 CVE-2026-56155 に記載された権限昇格の脆弱性に対処することを目的としています。
Active Directory Federation Services(AD FS)を使用している組織は、現在の監査モード期間を利用してDKMコンテナ権限を確認し、適用開始前に潜在的な互換性問題を特定するべきです。
展開スケジュール
強制モードは2026年10月のWindowsセキュリティアップデートから始まります。
組織への影響
AD FSを使用している組織は、強制モードでリメディエーションが適用される際にDKMコンテナ権限の変更が発生することがあります。2026年10月のアップデート以降、管理者が明示的にオプトアウトしない限り、サポートされるWindows Serverバージョンではデフォルトでリメディエーションが実行されます。Windows Server 2012およびWindows Server 2012 R2は手動でリメディケーションが必要で、自動的にリメディケーションされることはありません。
必要な行動/提言
AD FSを使用する組織は以下のことをすべきです:
  • 2026年7月のWindowsセキュリティアップデートまたはそれ以降のWindowsアップデートをAD FSサーバーにインストールしてください。
  • AD FSの管理イベントログでEvent ID 1132を確認し、DKMコンテナ権限に注意が必要であることを示します。
  • 2026年10月の執行モード開始前に、現在の監査モード段階で修復をレビューしテストします。
  • 以下のガイダンスを参照してください: CVE-2026-56155: AD FS Distributed Key ManagerコンテナのACLハードニング
コンプライアンスの考慮事項
コンプライアンス上の考慮事項は特定されていません。組織に応じた適切なレビューを行いましょう。