{"id":1470,"date":"2023-05-09T06:00:58","date_gmt":"2023-05-08T21:00:58","guid":{"rendered":"https:\/\/m365jp.xyz\/?p=1470"},"modified":"2023-05-09T06:02:56","modified_gmt":"2023-05-08T21:02:56","slug":"mc552226-latest-windows-hardening-guidance-and-key-dates","status":"publish","type":"post","link":"https:\/\/m365jp.net\/index.php\/2023-05-09-mc552226-latest-windows-hardening-guidance-and-key-dates","title":{"rendered":"MC552226 | Latest Windows hardening guidance and key dates"},"content":{"rendered":"<div class=\"postie-post\">\n<div>\n<hr>\n<table id=\"section\">\n<tbody>\n<tr>\n<th width=\"95%\">MC552226 | Latest Windows hardening guidance and key dates<\/th>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr>\n<table id=\"data\">\n<tbody>\n<tr>\n<th>Classification<\/th>\n<td>stayInformed<\/td>\n<\/tr>\n<tr>\n<th>Last Updated<\/th>\n<td>05\/08\/2023 20:23:31<\/td>\n<\/tr>\n<tr>\n<th>Start Time<\/th>\n<td>05\/08\/2023 20:23:29<\/td>\n<\/tr>\n<tr>\n<th>End Time<\/th>\n<td>05\/08\/2024 20:23:29<\/td>\n<\/tr>\n<tr>\n<th>Message Content<\/th>\n<td>\n<div>If you\u2019re an IT admin, you can consult the latest timeline of hardening changes as part of your security strategy. Last month, two areas entered their second hardening phase: Netlogon protocol, and certificate-based authentication. The article lists these   and the following hardening changes through January 2024. Other vulnerable areas undergoing hardening in the upcoming months are Kerberos PAC signatures and Active Directory (AD) permissions. Read  <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/latest-windows-hardening-guidance-and-key-dates\/ba-p\/3807832\" rel=\"noopener noreferrer\" target=\"_blank\">  Latest Windows hardening guidance and key dates<\/a> to find out details, KB numbers, and additional resources to help you prepare your organization for these changes.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>When will this happen:&nbsp;<\/b><\/div>\n<ul>\n<li>April 2023: Netlogon protocol and certificate-based authentication already entered their second hardening phase.&nbsp;<\/li>\n<li>June 2023: Netlogon protocol and Kerberos PAC signatures will undergo their third hardening phase.&nbsp;<\/li>\n<li>July 2023: Netlogon protocol and Kerberos PAC signatures will enter the fourth hardening phase. This will be the final enforcement phase for Netlogon protocol.&nbsp;<\/li>\n<li>October 2023: Kerberos PAC signatures will enter the final, full enforcement in this phase.&nbsp;<\/li>\n<li>November 2023: Certificate-based authentication will enter the final, full enforcement.&nbsp;<\/li>\n<li>January 2024: Active Directory (AD) permissions will enter final enforcement.&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div><b>How this will affect your organization:&nbsp;<\/b><\/div>\n<div>While these dates are already documented and publicly known, this article provides a centralized location where you can visualize all the upcoming hardening. This article is meant to help you keep your estate protected while you focus on your job. The   Windows message center will continue publishing updates for each of the listed vulnerable areas one by one to keep you informed of approaching milestone dates.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>What you need to do to prepare:&nbsp;<\/b><\/div>\n<div>Please visit and bookmark <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/latest-windows-hardening-guidance-and-key-dates\/ba-p\/3807832\" rel=\"noopener noreferrer\" target=\"_blank\">  Latest Windows hardening guidance and key dates<\/a>.&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>Additional information:&nbsp;<\/b><\/div>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows\/release-health\/windows-message-center\" rel=\"noopener noreferrer\" target=\"_blank\">Windows message center<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25\" rel=\"noopener noreferrer\" target=\"_blank\">KB5021130: How to manage the Netlogon protocol changes   related to CVE-2022-38023<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16\" rel=\"noopener noreferrer\" target=\"_blank\">KB5014754\u2015Certificate-based authentication changes   on Windows domain controllers<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5020805-how-to-manage-kerberos-protocol-changes-related-to-cve-2022-37967-997e9acc-67c5-48e1-8d0d-190269bf4efb#timing\" rel=\"noopener noreferrer\" target=\"_blank\">KB5020805: How to manage Kerberos protocol changes   related to CVE-2022-37967<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5008383-active-directory-permissions-updates-cve-2021-42291-536d5555-ffba-4248-a60e-d6cbc849cde1\" rel=\"noopener noreferrer\" target=\"_blank\">KB5008383\u2015Active Directory permissions updates (CVE-2021-42291)<\/a>&nbsp;<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<th>Machine Translation<\/th>\n<td>\n<div>IT \u7ba1\u7406\u8005\u306f\u3001\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u69c1\u9884\u6211\u753bh\u3068\u3057\u3066\u3001\u6d93\u5316\u306bv\u3059\u308b\u6700\u65b0\u306e\u30bf\u30a4\u30e0\u30e9\u30a4\u30f3\u3092\u53c2\u7167\u3067\u304d\u307e\u3059\u3002\u5148\u6708\u3001Netlogon \u30d7\u30ed\u30c8\u30b3\u30eb\u3068^\u660e\u4f83`\u30b9\u306eJ^\u3068\u3044\u3046 2 \u3064\u306eI\u57df\u304c 2 \u756a\u76ee\u306e\u5316\u30d5\u30a7`\u30ba\u306b\u5165\u308a\u307e\u3057\u305f\u3002\u3053\u306e\u4e8b\u3067\u306f\u30012024 \u5e74 1 \u6708\u307e\u3067\u306e\u3053\u308c\u3089\u306e\u6d93\u5374\u97e6\u5316\u306e\u6d93\u609a\u6454\u819c\u3044\u666eh\u660e\u3057\u307e\u3059\u3002\u4eca\u5f8c\u6570\u304b\u6708\u4ee5\u5185\u306b\u5316\u3055\u308c\u308b\u305d\u306e\u4ed6\u306e\u8106\u5f31\u306aI\u57df\u306f\u3001Kerberos PAC \u7f72\u540d\u3068\u30a2\u30af\u30c6\u30a3\u30d6 \u30c7\u30a3\u30ec\u30af\u30c8\u30ea (AD) \u30a2\u30af\u30bb\u30b9S\u53ef\u3067\u3059\u3002  <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/latest-windows-hardening-guidance-and-key-dates\/ba-p\/3807832\" rel=\"noopener noreferrer\" target=\"_blank\">  \u6700\u65b0\u306e Windows \u5316\u30ac\u30a4\u30c0\u30f3\u30b9\u3068\u91cd\u8981\u306a\u65e5\u4ed8<\/a> \u3092i\u3093\u3067\u3001\u3053\u308c\u3089\u306e\u6d93\u6d43\u00e0\u5e73M\u3092\u6d43\u5de5\u6bea\u97e6\u8258\u54ff\u8111\u3001KB \u756a\u53f7\u3001\u305d\u306e\u4ed6\u306e\u30ea\u30bd`\u30b9\u3092_J\u3057\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u306f\u3044\u3064\u8d77\u3053\u308a\u307e\u3059\u304b:&nbsp;<\/b><\/div>\n<ul>\n<li>2023 \u5e74 4 \u6708: Netlogon \u30d7\u30ed\u30c8\u30b3\u30eb\u3068^\u660e\u4f83`\u30b9\u306eJ^\u306f\u3001\u65e2\u306b 2 \u756a\u76ee\u306e\u5316\u30d5\u30a7`\u30ba\u306b\u5165\u3063\u3066\u3044\u307e\u3059\u3002&nbsp;<\/li>\n<li>2023 \u5e74 6 \u6708: Netlogon \u30d7\u30ed\u30c8\u30b3\u30eb\u3068 Kerberos PAC \u7f72\u540d\u306f\u3001\u7b2c 3 \u5316\u30d5\u30a7`\u30ba\u3092\u53d7\u3051\u307e\u3059\u3002&nbsp;<\/li>\n<li>2023 \u5e74 7 \u6708: Netlogon \u30d7\u30ed\u30c8\u30b3\u30eb\u3068 Kerberos PAC \u7f72\u540d\u306f\u3001\u7b2c 4 \u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5316\u30d5\u30a7`\u30ba\u306b\u5165\u308a\u307e\u3059\u3002\u3053\u308c\u306f\u3001Netlogon \u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u6700Km\u7528\u30d5\u30a7`\u30ba\u306b\u306a\u308a\u307e\u3059\u3002&nbsp;<\/li>\n<li>2023 \u5e74 10 \u6708: Kerberos PAC \u7f72\u540d\u306f\u3001\u3053\u306e\u30d5\u30a7`\u30ba\u3067\u6700K\u7684\u306a\u5b8c\u5168\u306am\u7528\u306b\u5165\u308a\u307e\u3059\u3002&nbsp;<\/li>\n<li>2023 \u5e74 11 \u6708: ^\u660e\u4f83`\u30b9\u306eJ^\u304c\u6700K\u7684\u306a\u5b8c\u5168\u306am\u7528\u306b\u5165\u308a\u307e\u3059\u3002&nbsp;<\/li>\n<li>2024 \u5e74 1 \u6708: \u30a2\u30af\u30c6\u30a3\u30d6 \u30c7\u30a3\u30ec\u30af\u30c8\u30ea (AD) \u30a2\u30af\u30bb\u30b9S\u53ef\u304c\u6700K\u7684\u306am\u7528\u306b\u5165\u308a\u307e\u3059\u3002&nbsp;<\/li>\n<\/ul>\n<div>&nbsp;<\/div>\n<div><b>\u3053\u308c\u304cM\u306b\u4e0e\u3048\u308b\u5f71:&nbsp;<\/b><\/div>\n<div>\u3053\u308c\u3089\u306e\u65e5\u4ed8\u306f\u65e2\u306b\u6587\u4e39\u81c1\u2481\u8bdd\u609a\u9165\u6901\u6b37\u76ae\u3044\u84fc\u5de5\u957f\u65a1\u4e8b\u3067\u306f\u3001\u4eca\u5f8c\u306e\u3059\u3079\u3066\u306e\u5316\u3092\u5316\u3067\u304d\u308b\u4e00\u5143\u7684\u306a\u93ca\u86f1\u5cc1\u2500\u7b4f\u84fc\u57c2\uffe5\u957f\u65a1\u4e8b\u306f\u3001\u4ed5\u4e8b\u306b\u96c6\u4e2d\u3057\u3066\u3044\u308bg\u3001b\u3092\u4fddo\u3059\u308b\u306e\u306b\u5f79\u7acb\u3064\u3053\u3068\u3092\u76ee\u7684\u3068\u3057\u3066\u3044\u307e\u3059\u3002Windows \u30e1\u30c3\u30bb`\u30b8 \u30bb\u30f3\u30bf`\u306f\u3001\u4e00E\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u8106\u5f31\u306aI\u57df\u3054\u3068\u306b\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092 1 \u3064\u305a\u3064k\u884c\u3057A\u3051\u3001\u30de\u30a4\u30eb\u30b9\u30c8`\u30f3\u306e\u65e5\u4ed8\u304c\u8fd1\u3065\u3044\u3066\u3044\u308b\u3053\u3068\u3092\u901a\u77e5\u3057\u307e\u3059\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u6d43\u5de5\u6bea\u90e1\u5e5b\u542e\u533e\u80dc\u957f:&nbsp;<\/b><\/div>\n<div><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/windows-it-pro-blog\/latest-windows-hardening-guidance-and-key-dates\/ba-p\/3807832\" rel=\"noopener noreferrer\" target=\"_blank\">\u6700\u65b0\u306e Windows \u5316\u30ac\u30a4\u30c0\u30f3\u30b9\u3068\u91cd\u8981\u306a\u65e5\u4ed8<\/a>\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u30d6\u30c3\u30af\u30de`\u30af\u3057\u3066\u304f\u3060\u3055\u3044\u3002&nbsp;<\/div>\n<div>&nbsp;<\/div>\n<div><b>\u8ffd\u52a0\u60c5:&nbsp;<\/b><\/div>\n<ul>\n<li><a href=\"https:\/\/learn.microsoft.com\/windows\/release-health\/windows-message-center\" rel=\"noopener noreferrer\" target=\"_blank\">\u30a6\u30a3\u30f3\u30c9\u30a6\u30ba \u30e1\u30c3\u30bb`\u30b8 \u30bb\u30f3\u30bf`<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25\" rel=\"noopener noreferrer\" target=\"_blank\">KB5021130:CVE-2022-38023\u306bvB\u3059\u308bNetlogon\u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u6d93\u86ac\u82be\u6067\u5de5\u6555\u6912<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16\" rel=\"noopener noreferrer\" target=\"_blank\">KB5014754-Windows\u30c9\u30e1\u30a4\u30f3\u30b3\u30f3\u30c8\u30ed`\u30e9`\u3067\u306e^\u660e\u4f83`\u30b9\u306eJ^\u306e\u6d93<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5020805-how-to-manage-kerberos-protocol-changes-related-to-cve-2022-37967-997e9acc-67c5-48e1-8d0d-190269bf4efb#timing\" rel=\"noopener noreferrer\" target=\"_blank\">KB5020805:CVE-2022-37967\u306bvB\u3059\u308bKerberos\u30d7\u30ed\u30c8\u30b3\u30eb\u306e\u6d93\u86ac\u82be\u6067\u5de5\u6555\u6912<\/a>&nbsp;<\/li>\n<li><a href=\"https:\/\/support.microsoft.com\/topic\/kb5008383-active-directory-permissions-updates-cve-2021-42291-536d5555-ffba-4248-a60e-d6cbc849cde1\" rel=\"noopener noreferrer\" target=\"_blank\">KB5008383-\u30a2\u30af\u30c6\u30a3\u30d6\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u30a2\u30af\u30bb\u30b9S\u53ef\u306e\u66f4\u65b0(CVE-2021-42291)<\/a>&nbsp;<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>MC552226 | Latest Windows hardening guidance and key dates Classification stayInformed Last Updated 05\/08\/2023 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1470","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/1470","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/comments?post=1470"}],"version-history":[{"count":0,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/posts\/1470\/revisions"}],"wp:attachment":[{"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/media?parent=1470"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/categories?post=1470"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/m365jp.net\/index.php\/wp-json\/wp\/v2\/tags?post=1470"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}