Microsoft will begin enforcing Active Directory Federation Services (AD FS) Distributed Key Manager (DKM) container access control list (ACL) hardening from 13 October 2026, marking the end of the audit period that started in July 2026.
This change addresses the elevation of privilege vulnerability documented in CVE-2026-56155
, and Kent SMEs running AD FS must review DKM container permissions and address compatibility issues before automatic remediation takes effect this week.
What Is the AD FS DKM Container ACL Hardening Change
Microsoft introduced an audit period in July 2026 for ACL hardening associated with CVE-2026-56155, and organisations using AD FS should use the remaining audit period to review DKM container permissions and address compatibility issues before enforcement begins
. The DKM container stores encryption keys used by AD FS to secure tokens, and inadequate permissions on this container create an elevation of privilege risk that attackers could exploit to compromise federated authentication across your organisation.
With the October 2026 Windows security update, supported versions of Windows Server will run remediation by default unless administrators explicitly opt out
. For Kent SMEs using AD FS for single sign-on with cloud services such as Microsoft 365, this enforcement could affect authentication flows if DKM container permissions have been customised beyond Microsoft’s recommended configuration.
Which Windows Server Versions Are Affected
For Windows Server 2016 and later, Microsoft documents automatic remediation of insecure AD FS DKM ACLs by 13 October 2026 unless an administrator opts out
. This includes:
- Windows Server 2016 with AD FS 4.0
- Windows Server 2019 with AD FS 4.0
- Windows Server 2022 with AD FS 4.0
- Windows Server 2025 with AD FS 5.0
Windows Server 2012 and Windows Server 2012 R2 still require manual remediation and will not be automatically remediated during enforcement mode
. Kent SMEs still running these older versions—which should already be planning migration ahead of the Windows Server 2012 R2 Extended Security Updates deadline on 13 October 2026—must apply manual remediation steps documented in Microsoft’s CVE guidance.
AD FS DKM ACL Enforcement and Windows Server 2022 End of Mainstream Support
The enforcement date coincides with another significant milestone:
on 13 October 2026, Windows Server 2022 will reach end of mainstream support, and the October 2026 security update will be the last mainstream support update available for this version
. Kent SMEs running Windows Server 2022 with AD FS will receive both the final mainstream security update and the DKM ACL hardening enforcement on the same day, making pre-deployment testing essential this week.
What Kent SMEs Must Do Before 13 October 2026
Review Current DKM Container Permissions During Audit Mode
During the audit phase, relevant findings appear in the AD FS/Admin log under Event ID 1132
. Your IT team or managed service provider should:
- Check the AD FS/Admin event log for Event ID 1132 entries that indicate non-compliant DKM container ACLs
- Document any custom permissions applied to the DKM container in Active Directory
- Identify service accounts or applications that rely on current DKM container permissions
- Test authentication flows in a non-production AD FS environment with hardened ACLs applied
Address Compatibility Issues Before Automatic Enforcement
If your organisation has customised DKM container permissions for legitimate operational reasons—such as backup software access or monitoring tools—you must either adjust those tools to work with the hardened ACLs or document a formal opt-out decision. Microsoft provides opt-out guidance for environments where automatic remediation would break critical business processes, but opting out leaves the elevation of privilege vulnerability unaddressed.
Deploy October 2026 Security Updates in a Controlled Manner
Kent SMEs should deploy the October 2026 Windows Server security updates to AD FS servers during a planned maintenance window with rollback capability. Test authentication to federated services—including Microsoft 365, Azure AD-integrated applications, and any third-party SAML or WS-Federation relying parties—before declaring the update successful. The September 2026 Patch Tuesday already addressed 973 vulnerabilities including two actively exploited zero-days, and October’s release will bring additional critical fixes alongside the AD FS enforcement.
Why AD FS Security Hardening Matters for UK SMEs
Active Directory Federation Services often serves as a critical trust boundary between on-premises identity infrastructure and cloud services. An elevation of privilege vulnerability in the DKM container could allow an attacker who has already gained limited access to your network to escalate privileges and forge authentication tokens, effectively compromising every federated service your organisation uses.
This enforcement arrives during a period of heightened regulatory scrutiny: the UK Cyber Security and Resilience Bill currently progressing through committee stage will impose mandatory incident reporting requirements, and
supply chain scrutiny, incident readiness, and baseline cybersecurity controls will matter more in everyday commercial relationships
. Kent SMEs that serve larger regulated organisations must demonstrate robust identity security practices, and addressing known elevation of privilege vulnerabilities is foundational.
Alternative Identity Architectures for Kent SMEs Reconsidering AD FS
Some Kent SMEs may use this enforcement as an opportunity to reconsider whether AD FS remains the appropriate federation solution for their needs. Microsoft has shifted emphasis toward Azure AD (now Microsoft Entra ID) for cloud-first authentication, and the automatic migration from SMS and voice MFA to passkeys that began 1 September 2026 reflects Microsoft’s move toward modern authentication methods that don’t require on-premises federation infrastructure.
Organisations still running AD FS primarily to support legacy applications or hybrid Exchange deployments should evaluate whether those dependencies can be addressed through Azure AD Connect cloud sync, Azure AD Application Proxy, or migration to Exchange Online. The operational complexity and security surface area of maintaining on-premises federation services may outweigh the benefits for many SMEs.
Support Deadlines Converging in October 2026
October 2026 represents an unprecedented convergence of support deadlines for Kent SMEs:
- Windows Server 2012 R2 Extended Security Updates end 13 October 2026
- Office 2021 and Office LTSC 2021 end of support in October 2026
- Windows Server 2022 end of mainstream support 13 October 2026
- AD FS DKM container ACL hardening enforcement 13 October 2026
- Exchange Server 2016 and 2019 Extended Security Updates Period 2 ends October 2026
This concentration of deadlines requires careful planning to avoid rushed migrations or inadequate testing. Kent SMEs should prioritise based on security risk: addressing actively exploited vulnerabilities and enforcement actions like the AD FS DKM hardening takes precedence over end-of-support planning for systems that will continue functioning (albeit without updates) after their deadline.
How Meridian Micro Can Help Kent SMEs Prepare for AD FS Enforcement
If your Kent business runs Active Directory Federation Services and you’re uncertain whether your DKM container permissions will be affected by the 13 October 2026 enforcement, or if you need help reviewing Event ID 1132 audit findings and testing the impact of hardened ACLs, Meridian Micro can assist. We support SMEs across Kent and the South East with Windows Server infrastructure, Active Directory management, and security hardening projects.
We can review your current AD FS configuration, test authentication flows with hardened DKM container ACLs in place, deploy the October 2026 security updates during a scheduled maintenance window, and help you evaluate whether modern cloud-based identity solutions might better serve your organisation’s needs. Call our Saltwood office on 01303 883111 to discuss your AD FS environment and ensure you’re prepared for the 13 October 2026 enforcement deadline.
