Hardening is a key element of our ongoing security strategy to help keep your estate protected while you focus on your job. Increasingly creative cyberthreats target weaknesses anywhere possible, from the chip to the cloud. Have you seen our publications on hardening on the Windows message center? Some of those recently enforced include DCOM authentication hardening and Netjoin: domain join hardening. Let's review vulnerable areas that are undergoing hardening in the upcoming months.
Hardening changes at a glance
Review the visual timeline to focus on the specific changes that are of interest to you. Find the details for each phase below.
![]()
A visual timeline of the hardening changes taking place in 2023
Hardening changes by month
Consult the details for all upcoming hardening changes by month to help you plan for each phase and final enforcement.
March 2023
- DCOM authentication hardening KB5004442 | Phase 3
Final enforcement: changes enabled by default with no ability to disable them. Assumes prior resolution of all compatibility issues.April 2023
- Netlogon protocol changes KB5021130 | Phase 2
Initial enforcement; removes the ability to disable RPC sealing by setting value 0 to the RequireSeal registry subkey.- Certificate-based authentication KB5014754 | Phase 2
Removes Disabled mode.June 2023
- Netlogon protocol changes KB5021130 | Phase 3
Enforcement by default. RequireSeal subkey will be moved to Enforcement mode unless you explicitly configure it to be under Compatibility mode.- Kerberos PAC Signatures KB5020805 | Phase 3
Removes the ability to disable PAC signature addition by setting the KrbtgtFullPacSignature subkey to a value of 0.July 2023
- Secure Boot bypass protections KB5025885 | Phase 2
Automated deployment of the revocation files and SafeOS dynamic update package for Window Recovery Environment (WinRE). New Event Log events will report on the success of revocation deployment.- Netlogon protocol changes KB5021130 | Phase 4
Final enforcement.RequireSeal subkey will be moved to Enforcement mode unless you explicitly configure it to be under Compatibility mode.Will remove the Compatibility mode (the ability to set value 1 to the RequireSeal registry subkey).
Editor's note (5.2.2023): The previous post incorrectly described the final enforcement phase for Netlogon protocol. We corrected this in this post to align with the official description documented in the corresponding KB article.- Kerberos PAC Signatures KB5020805 | Phase 4
Enforcement mode as default (KrbtgtFullPacSignature = 3), which you can override with an explicit Audit setting.October 2023
- Kerberos PAC Signatures KB5020805 | Phase 5
Final, full enforcement.November 2023
- Certificate-based authentication KB5014754 | Phase 3
Final, full enforcement.January 2024
- Active Directory (AD) permissions issue KB5008383 | Phase 5
Final enforcement.![]()
A visual timeline of the hardening changes taking place in 2024 with Phase 5 and Phase 3
First quarter of 2024
- Secure Boot bypass protections KB5025885 | Phase 3
Full, final enforcement.
Source:
Latest Windows hardening guidance and key dates - Microsoft Support
Last edited:






