What and why
In October 2026, Windows updates will begin Enforcement mode for AD FS Distributed Key Manager (DKM) container ACL hardening. This hardening change is designed to address the elevation of privilege vulnerability documented in
CVE-2026-56155 by automatically remediating insecure DKM container ACL configurations on supported Windows Server versions.
If your organization uses Active Directory Federation Services (AD FS), use the remaining Audit mode period to validate DKM container permissions, identify compatibility issues, and complete preparation before Enforcement mode begins.
Rollout schedule
Enforcement mode begins with the October 2026 Windows security update.
Impact on your organization
Organizations using AD FS might see changes to DKM container permissions when remediation is applied during Enforcement mode. During the October 2026 update, supported Windows Server versions will run remediation by default unless administrators explicitly opt out. Windows Server 2012 and Windows Server 2012 R2 still require manual remediation and will not be automatically remediated.
Action required/recommendations
Organizations using AD FS should: