90-Day Reminder: AD FS DKM container ACL hardening begins in October 2026

🚨 The Signal: Microsoft will automatically harden AD FS Distributed Key Manager (DKM) container permissions starting October 2026 to fix an elevation of privilege vulnerability (CVE-2026-56155). Organisations must review and test permissions now to avoid service disruption.

The Impact

Organisations using AD FS are affected, facing a critical security risk if DKM container permissions are not properly remediated, potentially leading to privilege escalation.

  • AD FS Administrators: Must review and test DKM container permissions to prevent service disruption.
  • Security Teams: Need to validate the remediation addresses CVE-2026-56155 and ensure secure AD FS configuration.
  • IT Operations: Must ensure Windows Server versions are updated to support automatic remediation or perform manual remediation for older versions.

The Action

  1. Install the July 2026 Windows security update or later on all AD FS servers.
  2. Review AD FS Admin event logs for Event ID 1132 to identify DKM container permission issues.
  3. Test the DKM container permission remediation during the current Audit mode phase.
  4. For Windows Server 2012/2012 R2, plan for manual DKM container remediation.
  5. Review CVE-2026-56155 guidance for full details on the vulnerability and remediation.

Domain: Entra · Impact: high · Workload: Entra ID · Essential Eight: Patch Operating Systems, Restrict Administrative Privileges · ISM: ISM-0445, ISM-1175, ISM-1380, ISM-1407, ISM-1501, ISM-1507, ISM-1508, ISM-1509, ISM-1621, ISM-1622, ISM-1623, ISM-1647, ISM-1648, ISM-1650, ISM-1654, ISM-1655, ISM-1686, ISM-1688, ISM-1689, ISM-1694, ISM-1695, ISM-1696, ISM-1701, ISM-1702, ISM-1877, ISM-1883, ISM-1889, ISM-1897, ISM-1898, ISM-1902