Blog

March 27, 2026
RC4 Deprecation: Phase 2 Is Here — And This Is Where Things Break (April 2026)

What’s Changing?

Microsoft is now enabling enforcement mode by default.
This means the Kerberosis shifting toward stronger, modern encryption whether environments are ready or not.

New Default Behavior:

Kerberos will now use AES-SHA1 (0x18) only as the default encryption.
Any accounts...

March 18, 2026
Making Lifecycle Workflows State-Aware with State Groups

Lifecycle Workflows in Microsoft Entra ID Governance are powerful—but they are also fundamentally trigger-driven.

Workflows are typically initiated by:

  • Attribute changes
  • Dates relative to employeeStartDate and employeeLeaveDateTime
  • Changes in group membership

This works well for simple...

Popular Tags
access reviewsactive directoryadaiassessmentauthenticationconditional accesscredentialsentitlement managementexternal sharinggroup migrationid governanceidentitykerberoslcwlicensingmdimfaprmfarc4sharepoint onlinesoasoft-deleteuser migration
Popular Tags
No tags found

Remind the blog authors to tag their posts!